mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -69,5 +69,3 @@ tags:
|
||||
- All_Changes.user
|
||||
risk_score: 36
|
||||
security_domain: threat
|
||||
supported_tas:
|
||||
- Splunk_TA_aws-kinesis-firehose
|
||||
|
||||
-2
@@ -69,5 +69,3 @@ tags:
|
||||
- All_Changes.user
|
||||
risk_score: 30
|
||||
security_domain: threat
|
||||
supported_tas:
|
||||
- Splunk_TA_aws-kinesis-firehose
|
||||
|
||||
@@ -40,7 +40,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
- Hermetic Wiper
|
||||
confidence: 80
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -76,6 +76,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 64
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -13,18 +13,18 @@ description: This analytic detects a potential suspicious modification of firewa
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*"
|
||||
Registry.registry_value_data = "*|Action=Allow|*" Registry.registry_value_data =
|
||||
"*|Dir=In|*" Registry.registry_value_data = "*|LPort=*" by _time span=1h Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_value_name Registry.process_guid Registry.registry_key_name Registry.registry_value_data
|
||||
| `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid,
|
||||
_time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest
|
||||
Processes.parent_process_name Processes.parent_process Processes.process_guid |
|
||||
`drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time
|
||||
dest user parent_process_name parent_process process_name process_path process proc_guid
|
||||
registry_path registry_value_name registry_value_data registry_key_name] | table
|
||||
_time dest user parent_process_name parent_process process_name process_path process
|
||||
proc_guid registry_path registry_value_name registry_value_data registry_key_name
|
||||
| `allow_inbound_traffic_by_firewall_rule_registry_filter`'
|
||||
"*|Dir=In|*" Registry.registry_value_data = "*|LPort=*" by _time span=1h Registry.dest
|
||||
Registry.user Registry.registry_path Registry.registry_value_name Registry.process_guid
|
||||
Registry.registry_key_name Registry.registry_value_data | `drop_dm_object_name(Registry)`
|
||||
|rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly`
|
||||
count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.process Processes.dest Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as
|
||||
proc_guid | fields _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data
|
||||
registry_key_name] | table _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data
|
||||
registry_key_name | `allow_inbound_traffic_by_firewall_rule_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
|
||||
@@ -48,8 +48,8 @@ tags:
|
||||
impact: 50
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: Suspicious firewall allow rule modifications were detected via the registry on endpoint
|
||||
$dest$ by user $user$.
|
||||
message: Suspicious firewall allow rule modifications were detected via the registry
|
||||
on endpoint $dest$ by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1021.001
|
||||
- T1021
|
||||
@@ -77,6 +77,4 @@ tags:
|
||||
- Registry.user
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -31,7 +31,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -67,6 +67,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -64,8 +64,6 @@ tags:
|
||||
- Registry.dest
|
||||
- Registry.registry_value_name
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -71,6 +71,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -71,6 +71,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -71,6 +71,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -71,6 +71,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -70,6 +70,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -70,6 +70,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -63,8 +63,6 @@ tags:
|
||||
- Registry.dest
|
||||
- Registry.registry_value_name
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -68,6 +68,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 40
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -70,6 +70,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -74,6 +74,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -76,6 +76,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 40
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -72,6 +72,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -71,6 +71,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -72,6 +72,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -75,6 +75,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -75,6 +75,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -73,6 +73,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -68,6 +68,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -75,6 +75,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -38,7 +38,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -76,6 +76,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -79,6 +79,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -35,7 +35,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Double Zero Destructor
|
||||
- Double Zero Destructor
|
||||
- Data Destruction
|
||||
- XMRig
|
||||
- Remcos
|
||||
@@ -85,6 +85,4 @@ tags:
|
||||
- Filesystem.user
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -28,7 +28,7 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -64,6 +64,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -74,3 +74,5 @@ tags:
|
||||
- Processes.parent_process_name
|
||||
risk_score: 36
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -55,8 +55,6 @@ tags:
|
||||
- Filesystem.user
|
||||
- Filesystem.file_path
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -9,8 +9,7 @@ datamodel:
|
||||
description: The search looks for modifications to registry keys that can be used
|
||||
to launch an application or service at system startup.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Registry
|
||||
where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce
|
||||
as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce
|
||||
OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls*
|
||||
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify*
|
||||
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet*
|
||||
@@ -24,13 +23,10 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
|
||||
AND Registry.registry_key_name="Load") OR (Registry.registry_path="*\\CurrentVersion"
|
||||
AND Registry.registry_key_name="Svchost") OR (Registry.registry_path="*\\CurrentControlSet\Control\Session
|
||||
Manager"AND Registry.registry_key_name="BootExecute") OR (Registry.registry_path="*\\Software\\Run"
|
||||
AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid Registry.registry_key_name
|
||||
| `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `registry_keys_used_for_persistence_filter`'
|
||||
AND Registry.registry_key_name="auto_update")) by Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
Registry.registry_key_name | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `registry_keys_used_for_persistence_filter`'
|
||||
how_to_implement: To successfully implement this search, you must be ingesting data
|
||||
that records registry activity from your hosts to populate the endpoint data model
|
||||
in the registry node. This is typically populated via endpoint detection-and-response
|
||||
@@ -95,5 +91,3 @@ tags:
|
||||
- Registry.user
|
||||
risk_score: 76
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -62,6 +62,4 @@ tags:
|
||||
- Registry.user
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -71,6 +71,4 @@ tags:
|
||||
- Registry.registry_key_name
|
||||
risk_score: 60
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -86,3 +86,5 @@ tags:
|
||||
- Processes.parent_process_name
|
||||
risk_score: 36
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -65,4 +65,6 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -82,3 +82,5 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -59,3 +59,5 @@ tags:
|
||||
- Filesystem.user
|
||||
risk_score: 70
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -32,7 +32,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Hermetic Wiper
|
||||
confidence: 90
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -68,6 +68,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 72
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -4,7 +4,7 @@ version: 3
|
||||
date: '2020-12-08'
|
||||
author: David Dorsey, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search looks for shim database files being written to default directories.
|
||||
The sdbinst.exe application is used to install shim database files (.sdb). According
|
||||
@@ -66,3 +66,5 @@ tags:
|
||||
- Filesystem.dest
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -94,5 +94,3 @@ tags:
|
||||
- cmd_line
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -4,7 +4,7 @@ version: 4
|
||||
date: '2020-07-22'
|
||||
author: Rico Valdez, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This search detects writes to the recycle bin by a process other than
|
||||
explorer.exe.
|
||||
@@ -70,3 +70,5 @@ tags:
|
||||
security_domain: endpoint
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -39,7 +39,7 @@ tags:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Hermetic Wiper
|
||||
confidence: 100
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -75,6 +75,4 @@ tags:
|
||||
- Registry.registry_value_name
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -6,23 +6,31 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: Adversaries may abuse mavinject.exe to inject malicious DLLs into running processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution (ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL).
|
||||
In addition to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an import table entry consisting of the specified DLL into the module at the given base address.
|
||||
During triage, review file modifcations and parallel processes.
|
||||
description: Adversaries may abuse mavinject.exe to inject malicious DLLs into running
|
||||
processes (i.e. Dynamic-link Library Injection), allowing for arbitrary code execution
|
||||
(ex. C:\Windows\system32\mavinject.exe PID /INJECTRUNNING PATH_DLL). In addition
|
||||
to Dynamic-link Library Injection, Mavinject.exe can also be abused to perform import
|
||||
descriptor injection via its /HMODULE command-line parameter (ex. mavinject.exe
|
||||
PID /HMODULE=BASE_ADDRESS PATH_DLL ORDINAL_NUMBER). This command would inject an
|
||||
import table entry consisting of the specified DLL into the module at the given
|
||||
base address. During triage, review file modifcations and parallel processes.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mavinject.exe Processes.process IN ("*injectrunning*", "*hmodule=0x*")
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_binary_proxy_execution_mavinject_dll_injection_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present, filter on DLL name or parent process.
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mavinject.exe
|
||||
Processes.process IN ("*injectrunning*", "*hmodule=0x*") by Processes.dest Processes.user
|
||||
Processes.parent_process_name Processes.process_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_binary_proxy_execution_mavinject_dll_injection_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present, filter on DLL name or parent
|
||||
process.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1218/013/
|
||||
- https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-1---mavinject---inject-dll-into-running-process
|
||||
- https://attack.mitre.org/techniques/T1218/013/
|
||||
- https://posts.specterops.io/mavinject-exe-functionality-deconstructed-c29ab2cf5c0e
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-1---mavinject---inject-dll-into-running-process
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
@@ -40,7 +48,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting load a DLL.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting load a DLL.
|
||||
mitre_attack_id:
|
||||
- T1218.013
|
||||
- T1218
|
||||
@@ -71,14 +80,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
+21
-16
@@ -6,23 +6,25 @@ author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies path traversal command-line execution. This technique was seen in malicious document that execute malicious code
|
||||
using msdt.exe and path traversal technique that serve as defense evasion. This TTP is a good pivot to look for more suspicious process and command-line
|
||||
that runs before and after this execution. This may help you to find possible downloaded malware or other lolbin execution.
|
||||
description: The following analytic identifies path traversal command-line execution.
|
||||
This technique was seen in malicious document that execute malicious code using
|
||||
msdt.exe and path traversal technique that serve as defense evasion. This TTP is
|
||||
a good pivot to look for more suspicious process and command-line that runs before
|
||||
and after this execution. This may help you to find possible downloaded malware
|
||||
or other lolbin execution.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/*" OR Processes.process="*\\..\\..\\..\\*" OR Processes.process="*\/\/..\/\/..\/\/..\/\/*" by
|
||||
Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process
|
||||
Processes.original_file_name Processes.process_id Processes.parent_process_id Processes.process_hash
|
||||
| `drop_dm_object_name("Processes")`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_command_and_scripting_interpreter_path_traversal_exec_filter`'
|
||||
as lastTime FROM datamodel=Endpoint.Processes where Processes.process="*\/..\/..\/..\/*"
|
||||
OR Processes.process="*\\..\\..\\..\\*" OR Processes.process="*\/\/..\/\/..\/\/..\/\/*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id
|
||||
Processes.process_hash | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_command_and_scripting_interpreter_path_traversal_exec_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product
|
||||
known_false_positives: Not known at this moment.
|
||||
known_false_positives: Not known at this moment.
|
||||
references:
|
||||
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
|
||||
tags:
|
||||
@@ -43,7 +45,8 @@ tags:
|
||||
impact: 90
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: A parent process $parent_process_name$ has spawned a child $process_name$ with path traversal commandline $process$ in $dest$
|
||||
message: A parent process $parent_process_name$ has spawned a child $process_name$
|
||||
with path traversal commandline $process$ in $dest$
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
nist:
|
||||
@@ -61,14 +64,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 90
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,19 +6,23 @@ author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies DCRat "forkbomb" payload feature.
|
||||
This technique was seen in dark crystal RAT backdoor capabilities where it will execute several cmd child process
|
||||
executing "notepad.exe & pause". This analytic detects the multiple cmd.exe and child process notepad.exe execution using batch script
|
||||
in the targeted host within 30s timeframe. this TTP can be a good pivot to check DCRat infection.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.parent_process) as parent_process values(Processes.parent_process_id) as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name= "notepad.exe") Processes.parent_process = "*.bat*"
|
||||
by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest Processes.user _time
|
||||
span=30s | where parent_process_id_count>= 10 AND process_id_count >=10
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_command_shell_dcrat_forkbomb_payload_filter`'
|
||||
description: The following analytic identifies DCRat "forkbomb" payload feature. This
|
||||
technique was seen in dark crystal RAT backdoor capabilities where it will execute
|
||||
several cmd child process executing "notepad.exe & pause". This analytic detects
|
||||
the multiple cmd.exe and child process notepad.exe execution using batch script
|
||||
in the targeted host within 30s timeframe. this TTP can be a good pivot to check
|
||||
DCRat infection.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
values(Processes.parent_process) as parent_process values(Processes.parent_process_id)
|
||||
as parent_process_id values(Processes.process_id) as process_id dc(Processes.parent_process_id)
|
||||
as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time)
|
||||
as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=
|
||||
"cmd.exe" (Processes.process_name = "notepad.exe" OR Processes.original_file_name=
|
||||
"notepad.exe") Processes.parent_process = "*.bat*" by Processes.parent_process_name
|
||||
Processes.process_name Processes.original_file_name Processes.parent_process Processes.dest
|
||||
Processes.user _time span=30s | where parent_process_id_count>= 10 AND process_id_count
|
||||
>=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |
|
||||
`security_content_ctime(lastTime)` | `windows_command_shell_dcrat_forkbomb_payload_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
@@ -45,7 +49,8 @@ tags:
|
||||
impact: 90
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: Multiple cmd.exe processes with child process of notepad.exe executed on $dest$
|
||||
message: Multiple cmd.exe processes with child process of notepad.exe executed on
|
||||
$dest$
|
||||
mitre_attack_id:
|
||||
- T1059.003
|
||||
- T1059
|
||||
@@ -75,3 +80,5 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 81
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -75,6 +75,4 @@ tags:
|
||||
- Registry.registry_value_data
|
||||
risk_score: 64
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
asset_type: Endpoint
|
||||
|
||||
@@ -6,13 +6,15 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic is to detect a suspicious registry modification to disable Lock Computer windows features.
|
||||
This registry modification prevent the user from locking its screen or computer that are being abused by several malware for example ransomware.
|
||||
This technique was used by threat actor to make its payload more impactful to the compromised host.
|
||||
description: This analytic is to detect a suspicious registry modification to disable
|
||||
Lock Computer windows features. This registry modification prevent the user from
|
||||
locking its screen or computer that are being abused by several malware for example
|
||||
ransomware. This technique was used by threat actor to make its payload more impactful
|
||||
to the compromised host.
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\DisableLockWorkstation"
|
||||
Registry.registry_value_data = "0x00000001"
|
||||
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
|
||||
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
|
||||
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
@@ -21,15 +23,14 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint
|
||||
proc_guid | fields _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data]
|
||||
| table _time dest user parent_process_name parent_process process_name process_path
|
||||
process proc_guid registry_path registry_value_name registry_value_data
|
||||
| `windows_disable_lock_workstation_feature_through_registry_filter`'
|
||||
process proc_guid registry_path registry_value_name registry_value_data | `windows_disable_lock_workstation_feature_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the Filesystem responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/
|
||||
- https://heimdalsecurity.com/blog/fatalrat-targets-telegram/
|
||||
- https://www.bleepingcomputer.com/news/security/in-dev-ransomware-forces-you-do-to-survey-before-unlocking-computer/
|
||||
- https://heimdalsecurity.com/blog/fatalrat-targets-telegram/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
@@ -51,17 +52,16 @@ tags:
|
||||
- Registry.registry_path
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest Registry.user
|
||||
- Processes.process_id
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.process_guid
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
impact: 70
|
||||
confidence: 70
|
||||
# (impact * confidence)/100
|
||||
confidence: 70
|
||||
risk_score: 49
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -78,4 +78,6 @@ tags:
|
||||
- CIS 3
|
||||
- CIS 5
|
||||
- CIS 16
|
||||
asset_type: Endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,33 +6,35 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic is to detect a suspicious registry modification to disable logoff feature in windows host.
|
||||
This registry when enable will prevent users to log off of the system by using any method,
|
||||
including programs run from the command line, such as scripts. It also disables or removes
|
||||
all menu items and buttons that log the user off of the system. This technique was seen abused by ransomware malware
|
||||
to make the compromised host un-useful and hard to remove other registry modification made on the machine that needs restart to take effect.
|
||||
This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
|
||||
and users that can modify this registry is needed.
|
||||
description: This analytic is to detect a suspicious registry modification to disable
|
||||
logoff feature in windows host. This registry when enable will prevent users to
|
||||
log off of the system by using any method, including programs run from the command
|
||||
line, such as scripts. It also disables or removes all menu items and buttons that
|
||||
log the user off of the system. This technique was seen abused by ransomware malware
|
||||
to make the compromised host un-useful and hard to remove other registry modification
|
||||
made on the machine that needs restart to take effect. This windows feature may
|
||||
implement by administrator in some server where shutdown is critical. In that scenario
|
||||
filter of machine and users that can modify this registry is needed.
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
|
||||
Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff")
|
||||
Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
|
||||
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
|
||||
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.process Processes.dest Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as
|
||||
proc_guid | fields _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data]
|
||||
| table _time dest user parent_process_name parent_process process_name process_path
|
||||
process proc_guid registry_path registry_value_name registry_value_data
|
||||
| `windows_disable_logoff_button_through_registry_filter`'
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
|
||||
Registry.registry_value_name IN ("NoLogOff", "StartMenuLogOff") Registry.registry_value_data
|
||||
= "0x00000001" by _time span=1h Registry.dest Registry.user Registry.registry_path
|
||||
Registry.registry_value_name Registry.registry_value_data Registry.process_guid
|
||||
| `drop_dm_object_name(Registry)` |rename process_guid as proc_guid |join proc_guid,
|
||||
_time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
by _time span=1h Processes.process_id Processes.process_name Processes.process Processes.dest
|
||||
Processes.parent_process_name Processes.parent_process Processes.process_guid |
|
||||
`drop_dm_object_name(Processes)` |rename process_guid as proc_guid | fields _time
|
||||
dest user parent_process_name parent_process process_name process_path process proc_guid
|
||||
registry_path registry_value_name registry_value_data] | table _time dest user parent_process_name
|
||||
parent_process process_name process_path process proc_guid registry_path registry_value_name
|
||||
registry_value_data | `windows_disable_logoff_button_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the Filesystem responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
|
||||
known_false_positives: This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
|
||||
and users that can modify this registry is needed.
|
||||
known_false_positives: This windows feature may implement by administrator in some
|
||||
server where shutdown is critical. In that scenario filter of machine and users
|
||||
that can modify this registry is needed.
|
||||
references:
|
||||
- https://www.hybrid-analysis.com/sample/e2d4018fd3bd541c153af98ef7c25b2bf4a66bc3bfb89e437cde89fd08a9dd7b/5b1f4d947ca3e10f22714774
|
||||
- https://malwiki.org/index.php?title=DigiPop.xp
|
||||
@@ -57,17 +59,16 @@ tags:
|
||||
- Registry.registry_path
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest Registry.user
|
||||
- Processes.process_id
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.process_guid
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
impact: 70
|
||||
confidence: 70
|
||||
# (impact * confidence)/100
|
||||
confidence: 70
|
||||
risk_score: 49
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -84,4 +85,6 @@ tags:
|
||||
- CIS 3
|
||||
- CIS 5
|
||||
- CIS 16
|
||||
asset_type: Endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,16 +6,18 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic is to detect a suspicious registry modification to disable shutdown button on the logon user.
|
||||
This technique was seen in several malware especially in ransomware family like killdisk malware variant to make the compromised host
|
||||
un-useful and hard to remove other registry modification made on the machine that needs restart to take effect.
|
||||
This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
|
||||
and users that can modify this registry is needed.
|
||||
description: This analytic is to detect a suspicious registry modification to disable
|
||||
shutdown button on the logon user. This technique was seen in several malware especially
|
||||
in ransomware family like killdisk malware variant to make the compromised host
|
||||
un-useful and hard to remove other registry modification made on the machine that
|
||||
needs restart to take effect. This windows feature may implement by administrator
|
||||
in some server where shutdown is critical. In that scenario filter of machine and
|
||||
users that can modify this registry is needed.
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\shutdownwithoutlogon"
|
||||
Registry.registry_value_data = "0x00000000")
|
||||
OR (Registry.registry_path="*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoClose" Registry.registry_value_data = "0x00000001")
|
||||
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.registry_value_data = "0x00000000") OR (Registry.registry_path="*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoClose"
|
||||
Registry.registry_value_data = "0x00000001") by _time span=1h Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
|
||||
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
|
||||
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
@@ -24,15 +26,15 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint
|
||||
proc_guid | fields _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data]
|
||||
| table _time dest user parent_process_name parent_process process_name process_path
|
||||
process proc_guid registry_path registry_value_name registry_value_data
|
||||
| `windows_disable_shutdown_button_through_registry_filter`'
|
||||
process proc_guid registry_path registry_value_name registry_value_data | `windows_disable_shutdown_button_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the Filesystem responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
|
||||
known_false_positives: This windows feature may implement by administrator in some server where shutdown is critical. In that scenario filter of machine
|
||||
and users that can modify this registry is needed.
|
||||
known_false_positives: This windows feature may implement by administrator in some
|
||||
server where shutdown is critical. In that scenario filter of machine and users
|
||||
that can modify this registry is needed.
|
||||
references:
|
||||
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.msil.screenlocker.a/
|
||||
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/ransom.msil.screenlocker.a/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
@@ -53,17 +55,16 @@ tags:
|
||||
- Registry.registry_path
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest Registry.user
|
||||
- Processes.process_id
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.process_guid
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
impact: 70
|
||||
confidence: 70
|
||||
# (impact * confidence)/100
|
||||
confidence: 70
|
||||
risk_score: 49
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -80,4 +81,6 @@ tags:
|
||||
- CIS 3
|
||||
- CIS 5
|
||||
- CIS 16
|
||||
asset_type: Endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
+23
-19
@@ -6,16 +6,20 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic is to detect a suspicious registry modification to disable windows features.
|
||||
These techniques are seen in several ransomware malware to impair the compromised host to make it hard for analyst to mitigate or response
|
||||
from the attack. Disabling these known features make the analysis and forensic response more hard. Disabling these feature is not so common but
|
||||
can still be implemented by the administrator for security purposes. In this scenario filters for users that are allowed doing this is needed.
|
||||
description: This analytic is to detect a suspicious registry modification to disable
|
||||
windows features. These techniques are seen in several ransomware malware to impair
|
||||
the compromised host to make it hard for analyst to mitigate or response from the
|
||||
attack. Disabling these known features make the analysis and forensic response more
|
||||
hard. Disabling these feature is not so common but can still be implemented by the
|
||||
administrator for security purposes. In this scenario filters for users that are
|
||||
allowed doing this is needed.
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*" OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\*"
|
||||
Registry.registry_value_name IN ("NoDesktop", "NoFind", "NoControlPanel", "NoFileMenu", "NoSetTaskbar", "NoTrayContextMenu",
|
||||
"TaskbarLockAll", "NoThemesTab","NoPropertiesMyDocuments","NoVisualStyleChoice","NoColorChoice","NoPropertiesMyDocuments")
|
||||
Registry.registry_value_data = "0x00000001"
|
||||
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
|
||||
OR Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\*"
|
||||
Registry.registry_value_name IN ("NoDesktop", "NoFind", "NoControlPanel", "NoFileMenu",
|
||||
"NoSetTaskbar", "NoTrayContextMenu", "TaskbarLockAll", "NoThemesTab","NoPropertiesMyDocuments","NoVisualStyleChoice","NoColorChoice","NoPropertiesMyDocuments")
|
||||
Registry.registry_value_data = "0x00000001" by _time span=1h Registry.dest Registry.user
|
||||
Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
|
||||
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
|
||||
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
@@ -24,8 +28,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint
|
||||
proc_guid | fields _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data]
|
||||
| table _time dest user parent_process_name parent_process process_name process_path
|
||||
process proc_guid registry_path registry_value_name registry_value_data
|
||||
| `windows_disable_windows_group_policy_features_through_registry_filter`'
|
||||
process proc_guid registry_path registry_value_name registry_value_data | `windows_disable_windows_group_policy_features_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the Filesystem responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
|
||||
@@ -55,17 +58,16 @@ tags:
|
||||
- Registry.registry_path
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest Registry.user
|
||||
- Processes.process_id
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.process_guid
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
impact: 70
|
||||
confidence: 70
|
||||
# (impact * confidence)/100
|
||||
confidence: 70
|
||||
risk_score: 49
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -82,4 +84,6 @@ tags:
|
||||
- CIS 3
|
||||
- CIS 5
|
||||
- CIS 16
|
||||
asset_type: Endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -69,5 +69,3 @@ tags:
|
||||
- Registry.registry_path
|
||||
risk_score: 24
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,24 +6,33 @@ author: Michael Haag, Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a recently disclosed arbitraty command execution using Windows msdt.exe - a Diagnostics Troubleshooting Wizard. The sample identified will use the ms-msdt:/ protocol handler to load msdt.exe to retrieve a remote payload.
|
||||
During triage, review file modifications for html. Identify parallel process execution that may be related, including an Office Product.
|
||||
description: The following analytic identifies a recently disclosed arbitraty command
|
||||
execution using Windows msdt.exe - a Diagnostics Troubleshooting Wizard. The sample
|
||||
identified will use the ms-msdt:/ protocol handler to load msdt.exe to retrieve
|
||||
a remote payload. During triage, review file modifications for html. Identify parallel
|
||||
process execution that may be related, including an Office Product.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msdt.exe
|
||||
Processes.process IN ("*msdt*","*ms-msdt:*","*ms-msdt:/id*","*ms-msdt:-id*","*/id*") AND (Processes.process="*IT_BrowseForFile=*" OR Processes.process="*IT_RebrowseForFile=*" OR Processes.process="*.xml*") AND Processes.process="*PCWDiagnostic*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `windows_execute_arbitrary_commands_with_msdt_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present, filter as needed. Added .xml to potentially capture any answer file usage. Remove as needed.
|
||||
Processes.process IN ("*msdt*","*ms-msdt:*","*ms-msdt:/id*","*ms-msdt:-id*","*/id*")
|
||||
AND (Processes.process="*IT_BrowseForFile=*" OR Processes.process="*IT_RebrowseForFile=*"
|
||||
OR Processes.process="*.xml*") AND Processes.process="*PCWDiagnostic*" by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `windows_execute_arbitrary_commands_with_msdt_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present, filter as needed. Added .xml
|
||||
to potentially capture any answer file usage. Remove as needed.
|
||||
references:
|
||||
- https://isc.sans.edu/diary/rss/28694
|
||||
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
|
||||
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
|
||||
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
|
||||
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
|
||||
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
|
||||
- https://isc.sans.edu/diary/rss/28694
|
||||
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
|
||||
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
|
||||
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
|
||||
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
|
||||
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190
|
||||
@@ -43,8 +52,8 @@ tags:
|
||||
impact: 100
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: A parent process $parent_process_name$ has spawned a child
|
||||
process $process_name$ on host $dest$ possibly indicative of indirect command execution.
|
||||
message: A parent process $parent_process_name$ has spawned a child process $process_name$
|
||||
on host $dest$ possibly indicative of indirect command execution.
|
||||
mitre_attack_id:
|
||||
- T1218
|
||||
nist:
|
||||
@@ -74,14 +83,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 100
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,30 +6,32 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: This analytic is to detect a suspicious registry modification to hide common windows notification feature from compromised host.
|
||||
This technique was seen in some ransomware family to add more impact to its payload that are visually seen by user aside from the encrypted files and
|
||||
ransomware notes. Even this a good anomaly detection, administrator may implement this changes for auditing or security reason. In this scenario filter is needed.
|
||||
description: This analytic is to detect a suspicious registry modification to hide
|
||||
common windows notification feature from compromised host. This technique was seen
|
||||
in some ransomware family to add more impact to its payload that are visually seen
|
||||
by user aside from the encrypted files and ransomware notes. Even this a good anomaly
|
||||
detection, administrator may implement this changes for auditing or security reason.
|
||||
In this scenario filter is needed.
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
|
||||
Registry.registry_value_name IN ("HideClock", "HideSCAHealth", "HideSCANetwork", "HideSCAPower", "HideSCAVolume")
|
||||
Registry.registry_value_data = "0x00000001"
|
||||
by _time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid | `drop_dm_object_name(Registry)` |rename process_guid as
|
||||
proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly` count
|
||||
FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
where Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\*"
|
||||
Registry.registry_value_name IN ("HideClock", "HideSCAHealth", "HideSCANetwork",
|
||||
"HideSCAPower", "HideSCAVolume") Registry.registry_value_data = "0x00000001" by
|
||||
_time span=1h Registry.dest Registry.user Registry.registry_path Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid | `drop_dm_object_name(Registry)`
|
||||
|rename process_guid as proc_guid |join proc_guid, _time [| tstats `security_content_summariesonly`
|
||||
count FROM datamodel=Endpoint.Processes by _time span=1h Processes.process_id Processes.process_name
|
||||
Processes.process Processes.dest Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_guid | `drop_dm_object_name(Processes)` |rename process_guid as
|
||||
proc_guid | fields _time dest user parent_process_name parent_process process_name
|
||||
process_path process proc_guid registry_path registry_value_name registry_value_data]
|
||||
| table _time dest user parent_process_name parent_process process_name process_path
|
||||
process proc_guid registry_path registry_value_name registry_value_data
|
||||
| `windows_hide_notification_features_through_registry_filter`'
|
||||
process proc_guid registry_path registry_value_name registry_value_data | `windows_hide_notification_features_through_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the Filesystem responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` node.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom.Win32.ONALOCKER.A/
|
||||
- https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/Ransom.Win32.ONALOCKER.A/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
@@ -51,17 +53,16 @@ tags:
|
||||
- Registry.registry_path
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest Registry.user
|
||||
- Processes.process_id
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.process_guid
|
||||
- Processes.process_guid
|
||||
security_domain: endpoint
|
||||
impact: 70
|
||||
confidence: 70
|
||||
# (impact * confidence)/100
|
||||
confidence: 70
|
||||
risk_score: 49
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -78,4 +79,6 @@ tags:
|
||||
- CIS 3
|
||||
- CIS 5
|
||||
- CIS 16
|
||||
asset_type: Endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
+10
-13
@@ -6,19 +6,18 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The search looks for the deletion of Windows Defender main profile within the registry.
|
||||
This was used by RAT malware across a fleet of endpoints. This particular
|
||||
behavior is typically executed when an adversary gains access to an endpoint
|
||||
and beings to perform execution. Usually, a batch (.bat) will be executed and multiple
|
||||
description: The search looks for the deletion of Windows Defender main profile within
|
||||
the registry. This was used by RAT malware across a fleet of endpoints. This particular
|
||||
behavior is typically executed when an adversary gains access to an endpoint and
|
||||
beings to perform execution. Usually, a batch (.bat) will be executed and multiple
|
||||
registry and scheduled task modifications will occur. During triage, review parallel
|
||||
processes and identify any further file modifications.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path = "*\\Policies\\Microsoft\\Windows Defender" Registry.action = deleted
|
||||
by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.user Registry.dest
|
||||
| `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_impair_defense_delete_win_defender_profile_registry_filter`'
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Policies\\Microsoft\\Windows
|
||||
Defender" Registry.action = deleted by Registry.registry_path Registry.registry_value_name
|
||||
Registry.registry_value_data Registry.process_guid Registry.action Registry.user
|
||||
Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_impair_defense_delete_win_defender_profile_registry_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node.
|
||||
@@ -71,5 +70,3 @@ tags:
|
||||
- Registry.action
|
||||
risk_score: 64
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
+23
-16
@@ -7,24 +7,28 @@ type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a modification in the Windows registry
|
||||
by the Applocker utility that contains details or registry data values related to denying the execution of several security products.
|
||||
This technique was seen in Azorult malware where it drops an xml Applocker policy that will deny several AV products and then loaded by using PowerShell Applocker
|
||||
commandlet.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
|
||||
where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group Policy Objects\\*" AND Registry.registry_path= "*}Machine\\Software\\Policies\\Microsoft\\Windows\\SrpV2*")
|
||||
OR Registry.registry_path="*\\Software\\Policies\\Microsoft\\Windows\\SrpV2*"
|
||||
AND Registry.registry_value_data = "*Action\=\"Deny\"*"
|
||||
AND Registry.registry_value_data IN("*O=SYMANTEC*","*O=MCAFEE*","*O=KASPERSKY*","*O=BLEEPING COMPUTER*", "*O=PANDA SECURITY*","*O=SYSTWEAK SOFTWARE*", "*O=TREND MICRO*", "*O=AVAST*", "*O=GRIDINSOFT*", "*O=MICROSOFT*", "*O=NANO SECURITY*", "*O=SUPERANTISPYWARE.COM*", "*O=DOCTOR WEB*", "*O=MALWAREBYTES*", "*O=ESET*", "*O=AVIRA*", "*O=WEBROOT*")
|
||||
by Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.registry_key_name Registry.dest
|
||||
| `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
by the Applocker utility that contains details or registry data values related to
|
||||
denying the execution of several security products. This technique was seen in Azorult
|
||||
malware where it drops an xml Applocker policy that will deny several AV products
|
||||
and then loaded by using PowerShell Applocker commandlet.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Group
|
||||
Policy Objects\\*" AND Registry.registry_path= "*}Machine\\Software\\Policies\\Microsoft\\Windows\\SrpV2*")
|
||||
OR Registry.registry_path="*\\Software\\Policies\\Microsoft\\Windows\\SrpV2*" AND
|
||||
Registry.registry_value_data = "*Action\=\"Deny\"*" AND Registry.registry_value_data
|
||||
IN("*O=SYMANTEC*","*O=MCAFEE*","*O=KASPERSKY*","*O=BLEEPING COMPUTER*", "*O=PANDA
|
||||
SECURITY*","*O=SYSTWEAK SOFTWARE*", "*O=TREND MICRO*", "*O=AVAST*", "*O=GRIDINSOFT*",
|
||||
"*O=MICROSOFT*", "*O=NANO SECURITY*", "*O=SUPERANTISPYWARE.COM*", "*O=DOCTOR WEB*",
|
||||
"*O=MALWAREBYTES*", "*O=ESET*", "*O=AVIRA*", "*O=WEBROOT*") by Registry.user Registry.registry_path
|
||||
Registry.registry_value_data Registry.action Registry.registry_key_name Registry.dest
|
||||
| `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_impair_defense_deny_security_software_with_applocker_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
|
||||
that this registry was included in your config files ex. sysmon config to be monitored.
|
||||
known_false_positives: False positives may be present based on organization use of Applocker. Filter as needed.
|
||||
known_false_positives: False positives may be present based on organization use of
|
||||
Applocker. Filter as needed.
|
||||
references:
|
||||
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
|
||||
- https://www.microsoftpressstore.com/articles/article.aspx?p=2228450&seqNum=11
|
||||
@@ -45,9 +49,10 @@ tags:
|
||||
impact: 100
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: Applocker registry modification to deny the action of several AV products on $dest$.
|
||||
message: Applocker registry modification to deny the action of several AV products
|
||||
on $dest$.
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562.001
|
||||
- T1562
|
||||
nist:
|
||||
- DE.CM
|
||||
@@ -74,4 +79,6 @@ tags:
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 100
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,19 +6,18 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The search looks for the Registry Key DefenderApiLogger or DefenderAuditLogger set to disable.
|
||||
This is consistent with RAT malware across a fleet of endpoints. This particular
|
||||
behavior is typically executed when an adversary gains access to an endpoint
|
||||
and beings to perform execution. Usually, a batch (.bat) will be executed and multiple
|
||||
registry and scheduled task modifications will occur. During triage, review parallel
|
||||
processes and identify any further file modifications.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
|
||||
where (Registry.registry_path = "*WMI\\Autologger\\DefenderApiLogger\\Start" OR Registry.registry_path = "*WMI\\Autologger\\DefenderAuditLogger\\Start") Registry.registry_value_data ="0x00000000"
|
||||
by Registry.registry_path Registry.registry_value_name Registry.registry_value_data Registry.process_guid Registry.action Registry.dest Registry.user
|
||||
| `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_impair_defenses_disable_win_defender_auto_logging_filter`'
|
||||
description: The search looks for the Registry Key DefenderApiLogger or DefenderAuditLogger
|
||||
set to disable. This is consistent with RAT malware across a fleet of endpoints.
|
||||
This particular behavior is typically executed when an adversary gains access to
|
||||
an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed
|
||||
and multiple registry and scheduled task modifications will occur. During triage,
|
||||
review parallel processes and identify any further file modifications.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Registry where (Registry.registry_path = "*WMI\\Autologger\\DefenderApiLogger\\Start"
|
||||
OR Registry.registry_path = "*WMI\\Autologger\\DefenderAuditLogger\\Start") Registry.registry_value_data
|
||||
="0x00000000" by Registry.registry_path Registry.registry_value_name Registry.registry_value_data
|
||||
Registry.process_guid Registry.action Registry.dest Registry.user | `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_impair_defenses_disable_win_defender_auto_logging_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node.
|
||||
@@ -71,5 +70,3 @@ tags:
|
||||
- Registry.action
|
||||
risk_score: 24
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -7,25 +7,25 @@ type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic detects programs that have been started by forfiles.exe.
|
||||
According to Microsoft, the 'The forfiles command lets you run a command on or pass
|
||||
According to Microsoft, the 'The forfiles command lets you run a command on or pass
|
||||
arguments to multiple files'. While this tool can be used to start legitimate programs,
|
||||
usually within the context of a batch script, it has been observed being used to evade
|
||||
protections on command line execution.
|
||||
usually within the context of a batch script, it has been observed being used to
|
||||
evade protections on command line execution.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*forfiles* /c *"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_path
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_indirect_command_execution_via_forfiles_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*forfiles*
|
||||
/c *" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.process_path | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_indirect_command_execution_via_forfiles_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the full process path in the process field of CIM's Process data model.
|
||||
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
Tune and filter known instances where forfiles.exe may be used.
|
||||
known_false_positives: Some legacy applications may be run using pcalua.exe.
|
||||
Similarly, forfiles.exe may be used in legitimate batch scripts. Filter these results as needed.
|
||||
known_false_positives: Some legacy applications may be run using pcalua.exe. Similarly,
|
||||
forfiles.exe may be used in legitimate batch scripts. Filter these results as needed.
|
||||
references:
|
||||
- https://twitter.com/KyleHanslovan/status/912659279806640128
|
||||
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/forfiles
|
||||
- https://twitter.com/KyleHanslovan/status/912659279806640128
|
||||
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/forfiles
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
@@ -43,21 +43,20 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
- Processes.process_path
|
||||
security_domain: endpoint
|
||||
impact: 50
|
||||
confidence: 50
|
||||
# (impact * confidence)/100
|
||||
confidence: 50
|
||||
risk_score: 25
|
||||
context:
|
||||
context:
|
||||
- Source:Endpoint
|
||||
- Stage:Defense Evasion
|
||||
message: The Program Compatability Assistant (pcalua.exe) launched the process $process_name$
|
||||
@@ -70,5 +69,7 @@ tags:
|
||||
- DE.AE
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 10
|
||||
- CIS 10
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,24 +6,25 @@ author: Eric McGinnis, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic detects programs that have been started by pcalua.exe.
|
||||
pcalua.exe is the Microsoft Windows Program Compatability Assistant. While this tool
|
||||
can be used to start legitimate programs, it has been observed being used to evade
|
||||
protections on command line execution.
|
||||
description: The following analytic detects programs that have been started by pcalua.exe.
|
||||
pcalua.exe is the Microsoft Windows Program Compatability Assistant. While this
|
||||
tool can be used to start legitimate programs, it has been observed being used to
|
||||
evade protections on command line execution.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*pcalua* -a*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_path
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_indirect_command_execution_via_pcalua_filter`'
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process="*pcalua*
|
||||
-a*" by Processes.dest Processes.user Processes.parent_process Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.process_path | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_indirect_command_execution_via_pcalua_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the full process path in the process field of CIM's Process data model.
|
||||
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
Tune and filter known instances where pcalua.exe may be used.
|
||||
known_false_positives: Some legacy applications may be run using pcalua.exe. Filter these results as needed.
|
||||
known_false_positives: Some legacy applications may be run using pcalua.exe. Filter
|
||||
these results as needed.
|
||||
references:
|
||||
- https://twitter.com/KyleHanslovan/status/912659279806640128
|
||||
- https://lolbas-project.github.io/lolbas/Binaries/Pcalua/
|
||||
- https://twitter.com/KyleHanslovan/status/912659279806640128
|
||||
- https://lolbas-project.github.io/lolbas/Binaries/Pcalua/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
@@ -41,21 +42,20 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process
|
||||
- Processes.parent_process_name
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
- Processes.process_path
|
||||
security_domain: endpoint
|
||||
impact: 50
|
||||
confidence: 50
|
||||
# (impact * confidence)/100
|
||||
confidence: 50
|
||||
risk_score: 25
|
||||
context:
|
||||
context:
|
||||
- Source:Endpoint
|
||||
- Stage:Defense Evasion
|
||||
message: The Program Compatability Assistant (pcalua.exe) launched the process $process_name$
|
||||
@@ -68,5 +68,7 @@ tags:
|
||||
- DE.AE
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 10
|
||||
- CIS 10
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,24 +6,27 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies modification of Windows registry
|
||||
using regedit.exe application with silent mode parameter. regedit.exe windows application is commonly used as GUI app to check or modify registry.
|
||||
This application is also has undocumented command-line parameter and one of those are silent mode parameter that performs action without stopping for confirmation with
|
||||
dialog box. Importing registry from .reg files need to monitor in a production environment since it can be used adversaries to import RMS registry in compromised host.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name="regedit.exe" OR Processes.original_file_name="regedit.exe")
|
||||
AND Processes.process="* /s *" AND Processes.process="*.reg*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_modify_registry_regedit_silent_reg_import_filter`'
|
||||
description: The following analytic identifies modification of Windows registry using
|
||||
regedit.exe application with silent mode parameter. regedit.exe windows application
|
||||
is commonly used as GUI app to check or modify registry. This application is also
|
||||
has undocumented command-line parameter and one of those are silent mode parameter
|
||||
that performs action without stopping for confirmation with dialog box. Importing
|
||||
registry from .reg files need to monitor in a production environment since it can
|
||||
be used adversaries to import RMS registry in compromised host.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name="regedit.exe" OR Processes.original_file_name="regedit.exe")
|
||||
AND Processes.process="* /s *" AND Processes.process="*.reg*" by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_modify_registry_regedit_silent_reg_import_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Administrators may execute this command that may cause some false positive. Filter as needed.
|
||||
known_false_positives: Administrators may execute this command that may cause some
|
||||
false positive. Filter as needed.
|
||||
references:
|
||||
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
|
||||
- https://www.techtarget.com/searchwindowsserver/tip/Command-line-options-for-Regeditexe
|
||||
@@ -44,7 +47,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: The regedit app was executed with silet mode parameter to import .reg file on $dest$.
|
||||
message: The regedit app was executed with silet mode parameter to import .reg file
|
||||
on $dest$.
|
||||
mitre_attack_id:
|
||||
- T1112
|
||||
nist:
|
||||
@@ -72,4 +76,6 @@ tags:
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -74,3 +74,5 @@ tags:
|
||||
risk_score: 25
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,27 +6,34 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following anaytic identifies MOFComp.exe loading a MOF file. The Managed Object Format (MOF) compiler parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository.
|
||||
Typically, MOFComp.exe does not reach out to the public internet or load a MOF file from User Profile paths.
|
||||
A filter and consumer is typically registered in WMI. Review parallel processes and query WMI subscriptions to gather artifacts.
|
||||
The default path of mofcomp.exe is C:\Windows\System32\wbem.
|
||||
description: The following anaytic identifies MOFComp.exe loading a MOF file. The
|
||||
Managed Object Format (MOF) compiler parses a file containing MOF statements and
|
||||
adds the classes and class instances defined in the file to the WMI repository.
|
||||
Typically, MOFComp.exe does not reach out to the public internet or load a MOF file
|
||||
from User Profile paths. A filter and consumer is typically registered in WMI. Review
|
||||
parallel processes and query WMI subscriptions to gather artifacts. The default
|
||||
path of mofcomp.exe is C:\Windows\System32\wbem.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where
|
||||
(Processes.parent_process_name IN ("cmd.exe", "powershell.exe") Processes.process_name=mofcomp.exe)
|
||||
OR (Processes.process_name=mofcomp.exe Processes.process IN ("*\\AppData\\Local\\*","*\\Users\\Public\\*", "*\\WINDOWS\\Temp\\*"))
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_mof_event_triggered_execution_via_wmi_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present from automation based applications (SCCM), filtering may be required. In addition, break the query out based on volume of usage. Filter process names or f
|
||||
as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name
|
||||
IN ("cmd.exe", "powershell.exe") Processes.process_name=mofcomp.exe) OR (Processes.process_name=mofcomp.exe
|
||||
Processes.process IN ("*\\AppData\\Local\\*","*\\Users\\Public\\*", "*\\WINDOWS\\Temp\\*"))
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_mof_event_triggered_execution_via_wmi_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present from automation based applications
|
||||
(SCCM), filtering may be required. In addition, break the query out based on volume
|
||||
of usage. Filter process names or f
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1546/003/
|
||||
- https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
|
||||
- https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp
|
||||
- https://pentestlab.blog/2020/01/21/persistence-wmi-event-subscription/
|
||||
- https://www.sakshamdixit.com/wmi-events/
|
||||
- https://attack.mitre.org/techniques/T1546/003/
|
||||
- https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
|
||||
- https://docs.microsoft.com/en-us/windows/win32/wmisdk/mofcomp
|
||||
- https://pentestlab.blog/2020/01/21/persistence-wmi-event-subscription/
|
||||
- https://www.sakshamdixit.com/wmi-events/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Living Off The Land
|
||||
@@ -44,7 +51,8 @@ tags:
|
||||
impact: 80
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ loading a MOF file.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ loading a MOF file.
|
||||
mitre_attack_id:
|
||||
- T1546.003
|
||||
nist:
|
||||
@@ -74,14 +82,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 64
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,21 +6,25 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies the usage of msiexec.exe using the /y switch parameter, which grants the ability for msiexec to load DLLRegisterServer.
|
||||
description: The following analytic identifies the usage of msiexec.exe using the
|
||||
/y switch parameter, which grants the ability for msiexec to load DLLRegisterServer.
|
||||
Upon triage, review parent process and capture any artifacts for further review.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msiexec`
|
||||
Processes.process IN ("*/y*", "*-y*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_msiexec_dllregisterserver_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: This analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. Filter as needed.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process
|
||||
IN ("*/y*", "*-y*") by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_msiexec_dllregisterserver_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: This analytic will need to be tuned for your environment based
|
||||
on legitimate usage of msiexec.exe. Filter as needed.
|
||||
references:
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows System Binary Proxy Execution MSIExec
|
||||
@@ -38,7 +42,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to register a file.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to register a file.
|
||||
mitre_attack_id:
|
||||
- T1218.007
|
||||
nist:
|
||||
@@ -68,14 +73,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,21 +6,25 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies msiexec.exe with http in the command-line. This procedure will utilize msiexec.exe to download a remote file and load it.
|
||||
During triage, review parallel processes and capture any artifacts on disk for review.
|
||||
description: The following analytic identifies msiexec.exe with http in the command-line.
|
||||
This procedure will utilize msiexec.exe to download a remote file and load it. During
|
||||
triage, review parallel processes and capture any artifacts on disk for review.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process IN ("*http://*", "*https://*")
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_msiexec_remote_download_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present, filter by destination or parent process as needed.
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process
|
||||
IN ("*http://*", "*https://*") by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_msiexec_remote_download_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present, filter by destination or parent
|
||||
process as needed.
|
||||
references:
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows System Binary Proxy Execution MSIExec
|
||||
@@ -38,7 +42,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to download a remote file.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to download a remote file.
|
||||
mitre_attack_id:
|
||||
- T1218.007
|
||||
nist:
|
||||
@@ -68,14 +73,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,20 +6,27 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies MSIExec spawning multiple discovery commands, including spawning Cmd.exe or PowerShell.exe. Typically, child processes are not common from MSIExec other than MSIExec spawning itself.
|
||||
description: The following analytic identifies MSIExec spawning multiple discovery
|
||||
commands, including spawning Cmd.exe or PowerShell.exe. Typically, child processes
|
||||
are not common from MSIExec other than MSIExec spawning itself.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=msiexec.exe Processes.process_name IN ("powershell.exe","cmd.exe", "nltest.exe","ipconfig.exe","systeminfo.exe")
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=msiexec.exe
|
||||
Processes.process_name IN ("powershell.exe","cmd.exe", "nltest.exe","ipconfig.exe","systeminfo.exe")
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_msiexec_spawn_discovery_command_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives will be present with MSIExec spawning Cmd or PowerShell. Filtering will be needed. In addition, add other known discovery processes to enhance query.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives will be present with MSIExec spawning Cmd or
|
||||
PowerShell. Filtering will be needed. In addition, add other known discovery processes
|
||||
to enhance query.
|
||||
references:
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows System Binary Proxy Execution MSIExec
|
||||
@@ -37,7 +44,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ running different discovery commands.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ running different discovery commands.
|
||||
mitre_attack_id:
|
||||
- T1218.007
|
||||
nist:
|
||||
@@ -67,14 +75,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,20 +6,25 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies the usage of msiexec.exe using the /z switch parameter, which grants the ability for msiexec to unload DLLRegisterServer.
|
||||
description: The following analytic identifies the usage of msiexec.exe using the
|
||||
/z switch parameter, which grants the ability for msiexec to unload DLLRegisterServer.
|
||||
Upon triage, review parent process and capture any artifacts for further review.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msiexec`
|
||||
Processes.process IN ("*/z*", "*-z*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process
|
||||
IN ("*/z*", "*-z*") by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_msiexec_unregister_dllregisterserver_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: This analytic will need to be tuned for your environment based on legitimate usage of msiexec.exe. Filter as needed.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: This analytic will need to be tuned for your environment based
|
||||
on legitimate usage of msiexec.exe. Filter as needed.
|
||||
references:
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
- https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows System Binary Proxy Execution MSIExec
|
||||
@@ -37,7 +42,8 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to unregister a file.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to unregister a file.
|
||||
mitre_attack_id:
|
||||
- T1218.007
|
||||
nist:
|
||||
@@ -67,14 +73,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 35
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,19 +6,23 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies odbcconf.exe, Windows Open Database Connectivity utility, utilizing the action function of regsvr to load a DLL.
|
||||
An example will look like - odbcconf.exe /A { REGSVR T1218-2.dll }.
|
||||
During triage, review parent process, parallel procesess and file modifications.
|
||||
description: The following analytic identifies odbcconf.exe, Windows Open Database
|
||||
Connectivity utility, utilizing the action function of regsvr to load a DLL. An
|
||||
example will look like - odbcconf.exe /A { REGSVR T1218-2.dll }. During triage,
|
||||
review parent process, parallel procesess and file modifications.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe
|
||||
Processes.process IN ("*/a *", "*-a*") Processes.process="*regsvr*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_odbcconf_load_dll_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present and filtering may need to occur based on legitimate application usage. Filter as needed.
|
||||
Processes.process IN ("*/a *", "*-a*") Processes.process="*regsvr*" by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_odbcconf_load_dll_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present and filtering may need to occur
|
||||
based on legitimate application usage. Filter as needed.
|
||||
references:
|
||||
- https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html
|
||||
- https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw
|
||||
@@ -43,7 +47,8 @@ tags:
|
||||
- T1218.008
|
||||
nist:
|
||||
- DE.CM
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to circumvent controls.
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
@@ -69,14 +74,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,18 +6,24 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies the odbcconf.exe, Windows Open Database Connectivity utility, loading up a resource file. The file extension is arbitrary and may be named anything. The resource file itself may have different commands supported by Odbcconf to load up a DLL (REGSVR) on disk or additional commands.
|
||||
During triage, review file modifications and parallel processes.
|
||||
description: The following analytic identifies the odbcconf.exe, Windows Open Database
|
||||
Connectivity utility, loading up a resource file. The file extension is arbitrary
|
||||
and may be named anything. The resource file itself may have different commands
|
||||
supported by Odbcconf to load up a DLL (REGSVR) on disk or additional commands.
|
||||
During triage, review file modifications and parallel processes.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=odbcconf.exe
|
||||
Processes.process IN ("*-f *","*/f *") Processes.process="*.rsp*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_odbcconf_load_response_file_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present and filtering may need to occur based on legitimate application usage. Filter as needed.
|
||||
Processes.process IN ("*-f *","*/f *") Processes.process="*.rsp*" by Processes.dest
|
||||
Processes.user Processes.parent_process_name Processes.process_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_odbcconf_load_response_file_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present and filtering may need to occur
|
||||
based on legitimate application usage. Filter as needed.
|
||||
references:
|
||||
- https://strontic.github.io/xcyclopedia/library/odbcconf.exe-07FBA12552331355C103999806627314.html
|
||||
- https://twitter.com/redcanary/status/1541838407894171650?s=20&t=kp3WBPtfnyA3xW7D7wx0uw
|
||||
@@ -42,7 +48,8 @@ tags:
|
||||
- T1218.008
|
||||
nist:
|
||||
- DE.CM
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to circumvent controls.
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
on endpoint $dest$ by user $user$ attempting to circumvent controls.
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
@@ -68,14 +75,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 42
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,24 +6,32 @@ author: Michael Haag, Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a Microsoft Office product spawning the Windows msdt.exe process. MSDT is a Diagnostics Troubleshooting Wizard native to Windows. This behavior is related to a recently identified sample utilizing protocol handlers to evade preventative controls, including if macros are disabled in the document.
|
||||
During triage, review file modifications for html. In addition, parallel processes including PowerShell and CertUtil.
|
||||
description: The following analytic identifies a Microsoft Office product spawning
|
||||
the Windows msdt.exe process. MSDT is a Diagnostics Troubleshooting Wizard native
|
||||
to Windows. This behavior is related to a recently identified sample utilizing protocol
|
||||
handlers to evade preventative controls, including if macros are disabled in the
|
||||
document. During triage, review file modifications for html. In addition, parallel
|
||||
processes including PowerShell and CertUtil.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","outlook.exe","mspub.exe","visio.exe") Processes.process_name=msdt.exe
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `windows_office_product_spawning_msdt_filter`'
|
||||
how_to_implement: how To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
IN ("winword.exe","excel.exe","powerpnt.exe","outlook.exe","mspub.exe","visio.exe")
|
||||
Processes.process_name=msdt.exe by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `windows_office_product_spawning_msdt_filter`'
|
||||
how_to_implement: how To successfully implement this search you need to be ingesting
|
||||
information on process that include the name of the process responsible for the
|
||||
changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
||||
In addition, confirm the latest CIM App 4.20 or higher is installed and the latest
|
||||
TA for the endpoint product.
|
||||
known_false_positives: False positives should be limited, however filter as needed.
|
||||
references:
|
||||
- https://isc.sans.edu/diary/rss/28694
|
||||
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
|
||||
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
|
||||
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
|
||||
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
|
||||
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
|
||||
- https://isc.sans.edu/diary/rss/28694
|
||||
- https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
|
||||
- https://twitter.com/nao_sec/status/1530196847679401984?s=20&t=ZiXYI4dQuA-0_dzQzSUb3A
|
||||
- https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
|
||||
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
|
||||
- https://strontic.github.io/xcyclopedia/library/msdt.exe-152D4C9F63EFB332CCB134C6953C0104.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Spearphishing Attachments
|
||||
@@ -44,8 +52,8 @@ tags:
|
||||
impact: 100
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: Office parent process $parent_process_name$ has spawned a child
|
||||
process $process_name$ on host $dest$.
|
||||
message: Office parent process $parent_process_name$ has spawned a child process
|
||||
$process_name$ on host $dest$.
|
||||
mitre_attack_id:
|
||||
- T1566
|
||||
- T1566.001
|
||||
@@ -76,14 +84,16 @@ tags:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.parent_process_name
|
||||
- Processes.parent_process
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 100
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -76,3 +76,5 @@ tags:
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,20 +6,21 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic is to look for known processes killed by industroyer2 malware.
|
||||
This technique was seen in the industroyer2 malware attack that tries to kill several processes
|
||||
of windows host machines related to the energy facility network. This anomaly might be a good
|
||||
indicator to check which process kill these processes or why the process was killed.
|
||||
search: '`sysmon` EventCode=5 process_name IN ("PServiceControl.exe", "PService_PPD.exe")
|
||||
| stats min(_time) as firstTime max(_time) as lastTime count by process_name process process_path process_guid process_id EventCode dest user_id
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `windows_processes_killed_by_industroyer2_malware_filter`'
|
||||
description: The following analytic is to look for known processes killed by industroyer2
|
||||
malware. This technique was seen in the industroyer2 malware attack that tries to
|
||||
kill several processes of windows host machines related to the energy facility network.
|
||||
This anomaly might be a good indicator to check which process kill these processes
|
||||
or why the process was killed.
|
||||
search: '`sysmon` EventCode=5 process_name IN ("PServiceControl.exe", "PService_PPD.exe")
|
||||
| stats min(_time) as firstTime max(_time) as lastTime count by process_name process
|
||||
process_path process_guid process_id EventCode dest user_id | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `windows_processes_killed_by_industroyer2_malware_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also
|
||||
required.
|
||||
known_false_positives: False positives are possible if legitimate applications are
|
||||
allowed to terminate this process during testing or updates. Filter as needed based on paths that
|
||||
are used legitimately.
|
||||
allowed to terminate this process during testing or updates. Filter as needed based
|
||||
on paths that are used legitimately.
|
||||
references:
|
||||
- https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
|
||||
tags:
|
||||
@@ -69,3 +70,5 @@ tags:
|
||||
- Processes.process_guid
|
||||
risk_score: 36
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -79,3 +79,5 @@ tags:
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,18 +6,27 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies a process attempting to delete a scheduled task SD (Security Descriptor) from within the registry path of that task.
|
||||
This may occur from a non-standard process running and may not come from reg.exe. This particular behavior will remove the actual Task Name from the Task Scheduler GUI and from the command-line query - schtasks.exe /query.
|
||||
In addition, in order to perform this action, the user context will need to be SYSTEM.
|
||||
description: The following analytic identifies a process attempting to delete a scheduled
|
||||
task SD (Security Descriptor) from within the registry path of that task. This may
|
||||
occur from a non-standard process running and may not come from reg.exe. This particular
|
||||
behavior will remove the actual Task Name from the Task Scheduler GUI and from the
|
||||
command-line query - schtasks.exe /query. In addition, in order to perform this
|
||||
action, the user context will need to be SYSTEM.
|
||||
search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry
|
||||
where Registry.registry_path IN ("*\\Schedule\\TaskCache\\Tree\\*") Registry.user="SYSTEM" Registry.registry_value_name="SD" (Registry.action=Deleted OR Registry.action=modified)
|
||||
by _time Registry.dest Registry.process_guid Registry.user Registry.registry_path Registry.registry_value_name Registry.registry_key_name Registry.registry_value_data Registry.status Registry.action
|
||||
| `drop_dm_object_name(Registry)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_registry_delete_task_sd_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives should be limited as the activity is not common to delete ONLY the SD from the registry. Filter as needed. Update the analytic Modified or Deleted values based on product that is in the datamodel.
|
||||
where Registry.registry_path IN ("*\\Schedule\\TaskCache\\Tree\\*") Registry.user="SYSTEM"
|
||||
Registry.registry_value_name="SD" (Registry.action=Deleted OR Registry.action=modified)
|
||||
by _time Registry.dest Registry.process_guid Registry.user Registry.registry_path
|
||||
Registry.registry_value_name Registry.registry_key_name Registry.registry_value_data
|
||||
Registry.status Registry.action | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_registry_delete_task_sd_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives should be limited as the activity is not common
|
||||
to delete ONLY the SD from the registry. Filter as needed. Update the analytic Modified
|
||||
or Deleted values based on product that is in the datamodel.
|
||||
references:
|
||||
- https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/
|
||||
- https://gist.github.com/MHaggis/5f7fd6745915166fc6da863d685e2728
|
||||
@@ -45,7 +54,7 @@ tags:
|
||||
- T1562
|
||||
nist:
|
||||
- DE.CM
|
||||
message: A scheduled task security descriptor was deleted from the registry on $dest$.
|
||||
message: A scheduled task security descriptor was deleted from the registry on $dest$.
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
@@ -61,10 +70,12 @@ tags:
|
||||
- Registry.registry_key_name
|
||||
- Registry.registry_value_name
|
||||
- Registry.dest
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process_id
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.dest
|
||||
- Processes.process_guid
|
||||
- Processes.process_guid
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -76,3 +76,5 @@ tags:
|
||||
risk_score: 80
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,23 +6,25 @@ author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies RDPWInst.exe tool, which is a RDP wrapper library tool designed to enable remote
|
||||
desktop host support and concurrent RDP session on reduced functionality system. Unfortunately, this open project was abused by adversaries
|
||||
to enable RDP connection to the targeted host for remote access and potentially be for lateral movement.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name="RDPWInst.exe" OR Processes.original_file_name="RDPWInst.exe")
|
||||
AND Processes.process IN ("* -i*", "* -s*", "* -o*", "* -w*", "* -r*")
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_remote_service_rdpwinst_tool_execution_filter`'
|
||||
description: The following analytic identifies RDPWInst.exe tool, which is a RDP wrapper
|
||||
library tool designed to enable remote desktop host support and concurrent RDP session
|
||||
on reduced functionality system. Unfortunately, this open project was abused by
|
||||
adversaries to enable RDP connection to the targeted host for remote access and
|
||||
potentially be for lateral movement.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name="RDPWInst.exe" OR Processes.original_file_name="RDPWInst.exe")
|
||||
AND Processes.process IN ("* -i*", "* -s*", "* -o*", "* -w*", "* -r*") by Processes.dest
|
||||
Processes.user Processes.parent_process Processes.process_name Processes.original_file_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_remote_service_rdpwinst_tool_execution_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: This tool was designed for home usage and not commonly seen in production environment. Filter as needed.
|
||||
known_false_positives: This tool was designed for home usage and not commonly seen
|
||||
in production environment. Filter as needed.
|
||||
references:
|
||||
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
|
||||
tags:
|
||||
@@ -71,4 +73,6 @@ tags:
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 81
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -7,25 +7,27 @@ type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic is to identify a modification in the Windows firewall
|
||||
to enable remote desktop protocol on a targeted machine. This technique was seen in several adversaries, malware or red teamer
|
||||
to remotely access the compromised or targeted host by allowing this protocol in firewall. Even this protocol might be allowed in some
|
||||
production environment, This TTP behavior is a good pivot to check who and why the user want to enable this feature through firewall which is also common traits
|
||||
of attack to start lateral movement.
|
||||
to enable remote desktop protocol on a targeted machine. This technique was seen
|
||||
in several adversaries, malware or red teamer to remotely access the compromised
|
||||
or targeted host by allowing this protocol in firewall. Even this protocol might
|
||||
be allowed in some production environment, This TTP behavior is a good pivot to
|
||||
check who and why the user want to enable this feature through firewall which is
|
||||
also common traits of attack to start lateral movement.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as cmdline
|
||||
values(Processes.parent_process_name) as parent_process values(Processes.process_name)
|
||||
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = "netsh.exe" OR Processes.original_file_name= "netsh.exe") AND Processes.process = "*firewall*" AND Processes.process = "*add*" AND Processes.process = "*protocol=TCP*"
|
||||
AND Processes.process = "*localport=3389*" AND Processes.process = "*action=allow*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
where (Processes.process_name = "netsh.exe" OR Processes.original_file_name= "netsh.exe")
|
||||
AND Processes.process = "*firewall*" AND Processes.process = "*add*" AND Processes.process
|
||||
= "*protocol=TCP*" AND Processes.process = "*localport=3389*" AND Processes.process
|
||||
= "*action=allow*" by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_remote_services_allow_rdp_in_firewall_filter`'
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_remote_services_allow_rdp_in_firewall_filter`'
|
||||
how_to_implement: To successfully implement this search, you must be ingesting data
|
||||
that records process activity from your hosts to populate the endpoint data model
|
||||
in the processes node. If you are using Sysmon, you must have at least version 6.0.4
|
||||
of the Sysmon TA.
|
||||
known_false_positives: administrators may enable or disable this feature that may cause some false positive.
|
||||
known_false_positives: administrators may enable or disable this feature that may
|
||||
cause some false positive.
|
||||
references:
|
||||
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
|
||||
tags:
|
||||
@@ -72,3 +74,5 @@ tags:
|
||||
- Processes.user
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -73,3 +73,5 @@ tags:
|
||||
risk_score: 48
|
||||
security_domain: endpoint
|
||||
asset_type: Endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -4,7 +4,7 @@ version: 1
|
||||
date: '2020-11-06'
|
||||
author: Rod Soto, Jose Hernandez, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The search looks for a Windows Security Account Manager (SAM) was stopped
|
||||
via command-line. This is consistent with Ryuk infections across a fleet of endpoints.
|
||||
@@ -68,3 +68,5 @@ tags:
|
||||
- Processes.user
|
||||
risk_score: 70
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,17 +6,22 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifes a new kernel driver being added to Windows using sc.exe.
|
||||
Adding a Kernel driver is not common day to day and should be investigated to further understand the source.
|
||||
description: The following analytic identifes a new kernel driver being added to Windows
|
||||
using sc.exe. Adding a Kernel driver is not common day to day and should be investigated
|
||||
to further understand the source.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sc.exe
|
||||
Processes.process="*kernel*" by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_service_create_kernel_mode_driver_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present based on common applications adding new drivers, however, filter as needed.
|
||||
Processes.process="*kernel*" by Processes.dest Processes.user Processes.parent_process_name
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_service_create_kernel_mode_driver_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: False positives may be present based on common applications
|
||||
adding new drivers, however, filter as needed.
|
||||
references:
|
||||
- https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/
|
||||
tags:
|
||||
@@ -36,7 +41,8 @@ tags:
|
||||
impact: 60
|
||||
kill_chain_phases:
|
||||
- Installation
|
||||
message: Service control, $process_name$, loaded a new kernel mode driver on $dest$ by $user$.
|
||||
message: Service control, $process_name$, loaded a new kernel mode driver on $dest$
|
||||
by $user$.
|
||||
mitre_attack_id:
|
||||
- T1543.003
|
||||
- T1543
|
||||
@@ -61,11 +67,13 @@ tags:
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 48
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -11,13 +11,13 @@ description: The following analytic identifies Windows Service Control, `sc.exe`
|
||||
instances of service enumeration of attempts to stop a service and then delete it.
|
||||
Adversaries utilize this technique to terminate security services or other related
|
||||
services to continue there objective and evade detections.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = sc.exe OR Processes.original_file_name = sc.exe) Processes.process="* delete *" by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_service_stop_by_deletion_filter`'
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = sc.exe OR Processes.original_file_name = sc.exe)
|
||||
Processes.process="* delete *" by Processes.dest Processes.user Processes.parent_process
|
||||
Processes.process_name Processes.original_file_name Processes.process Processes.process_id
|
||||
Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_service_stop_by_deletion_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
@@ -73,3 +73,5 @@ tags:
|
||||
- Processes.user
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,22 +6,26 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies Windows commandlined to logoff a windows host machine.
|
||||
This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact,
|
||||
interrupt access, aid destruction of the system like wiping disk or inhibit system recovery.
|
||||
This TTP is a good pivot to check why application trigger this commandline which is not so common way to logoff a machine.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
description: The following analytic identifies Windows commandlined to logoff a windows
|
||||
host machine. This technique was seen in several APT, RAT like dcrat and other commodity
|
||||
malware to shutdown the machine to add more impact, interrupt access, aid destruction
|
||||
of the system like wiping disk or inhibit system recovery. This TTP is a good pivot
|
||||
to check why application trigger this commandline which is not so common way to
|
||||
logoff a machine.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe)
|
||||
Processes.process="*shutdown*" Processes.process="* /l*" Processes.process="* /t*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_system_logoff_commandline_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
known_false_positives: Administrator may execute this commandline to trigger shutdown, logoff or restart the host machine.
|
||||
known_false_positives: Administrator may execute this commandline to trigger shutdown,
|
||||
logoff or restart the host machine.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1529/
|
||||
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
|
||||
@@ -71,3 +75,5 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 56
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,23 +6,27 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies Windows commandlined to reboot a windows host machine.
|
||||
This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact,
|
||||
interrupt access, aid destruction of the system like wiping disk or inhibit system recovery.
|
||||
This TTP is a good pivot to check why application trigger this commandline which is not so common way to reboot a machine.
|
||||
Compare to shutdown and logoff shutdown.exe feature, reboot seen in some automation script like ansible to reboot the machine.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
description: The following analytic identifies Windows commandlined to reboot a windows
|
||||
host machine. This technique was seen in several APT, RAT like dcrat and other commodity
|
||||
malware to shutdown the machine to add more impact, interrupt access, aid destruction
|
||||
of the system like wiping disk or inhibit system recovery. This TTP is a good pivot
|
||||
to check why application trigger this commandline which is not so common way to
|
||||
reboot a machine. Compare to shutdown and logoff shutdown.exe feature, reboot seen
|
||||
in some automation script like ansible to reboot the machine.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe)
|
||||
Processes.process="*shutdown*" Processes.process="* /r*" Processes.process="* /t*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_system_reboot_commandline_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
known_false_positives: Administrator may execute this commandline to trigger shutdown or restart the host machine.
|
||||
known_false_positives: Administrator may execute this commandline to trigger shutdown
|
||||
or restart the host machine.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1529/
|
||||
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
|
||||
@@ -72,3 +76,5 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 30
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,22 +6,26 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies Windows commandlined to shutdown a windows host machine.
|
||||
This technique was seen in several APT, RAT like dcrat and other commodity malware to shutdown the machine to add more impact,
|
||||
interrupt access, aid destruction of the system like wiping disk or inhibit system recovery.
|
||||
This TTP is a good pivot to check why application trigger this commandline which is not so common way to shutdown a machine.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe) Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
description: The following analytic identifies Windows commandlined to shutdown a
|
||||
windows host machine. This technique was seen in several APT, RAT like dcrat and
|
||||
other commodity malware to shutdown the machine to add more impact, interrupt access,
|
||||
aid destruction of the system like wiping disk or inhibit system recovery. This
|
||||
TTP is a good pivot to check why application trigger this commandline which is not
|
||||
so common way to shutdown a machine.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where (Processes.process_name = shutdown.exe OR Processes.original_file_name = shutdown.exe)
|
||||
Processes.process="*shutdown*" Processes.process="* /s*" Processes.process="* /t*"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_system_shutdown_commandline_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
known_false_positives: Administrator may execute this commandline to trigger shutdown or restart the host machine.
|
||||
known_false_positives: Administrator may execute this commandline to trigger shutdown
|
||||
or restart the host machine.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1529/
|
||||
- https://www.mandiant.com/resources/analyzing-dark-crystal-rat-backdoor
|
||||
@@ -71,3 +75,5 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 49
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,19 +6,19 @@ author: Teoderick Contreras, Splunk
|
||||
type: Anomaly
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies DCRat delay time tactics using w32tm.
|
||||
This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe application to delay the execution of its payload like
|
||||
c2 communication , beaconing and execution. This anomaly detection may help the analyst to check other possible event like the process who
|
||||
execute this command that may lead to DCRat attack.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process= "* /computer:localhost *"
|
||||
Processes.process= "* /period:*" Processes.process= "* /dataonly *" Processes.process= "* /samples:*"
|
||||
by Processes.parent_process Processes.process_name Processes.original_file_name Processes.process
|
||||
Processes.process_id Processes.parent_process_id Processes.dest Processes.user
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_system_time_discovery_w32tm_delay_filter`'
|
||||
description: The following analytic identifies DCRat delay time tactics using w32tm.
|
||||
This technique was seen in DCRAT malware where it uses stripchart function of w32tm.exe
|
||||
application to delay the execution of its payload like c2 communication , beaconing
|
||||
and execution. This anomaly detection may help the analyst to check other possible
|
||||
event like the process who execute this command that may lead to DCRat attack.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where Processes.process_name = w32tm.exe Processes.process= "* /stripchart *" Processes.process=
|
||||
"* /computer:localhost *" Processes.process= "* /period:*" Processes.process= "*
|
||||
/dataonly *" Processes.process= "* /samples:*" by Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `windows_system_time_discovery_w32tm_delay_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
@@ -45,7 +45,8 @@ tags:
|
||||
impact: 60
|
||||
kill_chain_phases:
|
||||
- Reconnaissance
|
||||
message: Process name w32tm.exe is using suspcicious command line arguments $process$ on host $dest$.
|
||||
message: Process name w32tm.exe is using suspcicious command line arguments $process$
|
||||
on host $dest$.
|
||||
mitre_attack_id:
|
||||
- T1124
|
||||
nist:
|
||||
@@ -74,3 +75,5 @@ tags:
|
||||
- Processes.parent_process_id
|
||||
risk_score: 36
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -6,23 +6,25 @@ author: Teoderick Contreras, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Endpoint
|
||||
description: The following analytic identifies net.exe updating user account policies for password requirement with non-expiring password.
|
||||
This technique was seen in several adversaries and malware like Azorult to maintain the foothold (persistence), gaining privilege escalation, defense evasion and
|
||||
possible for lateral movement for specific users or created user account on the targeted host. This TTP detections is a good pivot to see further what other events that users
|
||||
executes on the machines.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where `process_net`
|
||||
AND Processes.process="* accounts *" AND Processes.process="* /maxpwage:unlimited"
|
||||
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
description: The following analytic identifies net.exe updating user account policies
|
||||
for password requirement with non-expiring password. This technique was seen in
|
||||
several adversaries and malware like Azorult to maintain the foothold (persistence),
|
||||
gaining privilege escalation, defense evasion and possible for lateral movement
|
||||
for specific users or created user account on the targeted host. This TTP detections
|
||||
is a good pivot to see further what other events that users executes on the machines.
|
||||
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
|
||||
min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
|
||||
where `process_net` AND Processes.process="* accounts *" AND Processes.process="*
|
||||
/maxpwage:unlimited" by Processes.dest Processes.user Processes.parent_process Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_valid_account_with_never_expires_password_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
known_false_positives: This behavior is not commonly seen in production environment and not advisable, filter as needed.
|
||||
known_false_positives: This behavior is not commonly seen in production environment
|
||||
and not advisable, filter as needed.
|
||||
references:
|
||||
- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/
|
||||
- https://docs.microsoft.com/en-us/troubleshoot/windows-server/networking/net-commands-on-operating-systems
|
||||
@@ -73,4 +75,6 @@ tags:
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
risk_score: 100
|
||||
security_domain: endpoint
|
||||
security_domain: endpoint
|
||||
supported_tas:
|
||||
- Splunk_TA_microsoft_sysmon
|
||||
|
||||
@@ -87,3 +87,5 @@ tags:
|
||||
- user
|
||||
risk_score: 15
|
||||
security_domain: threat
|
||||
supported_tas:
|
||||
- Splunk_TA_nginx
|
||||
|
||||
@@ -6,18 +6,19 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Web
|
||||
description: The following analytic is static indicators related to CVE-2022-22963, Spring4Shell. The 3 indicators provide an amount of fidelity that source IP is attemping to exploit a web shell on the destination.
|
||||
The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity.
|
||||
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET")
|
||||
Web.url IN ("*tomcatwar.jsp*","*poc.jsp*","*shell.jsp*")
|
||||
by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest
|
||||
sourcetype
|
||||
| `drop_dm_object_name("Web")`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `spring4shell_payload_url_request_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel.
|
||||
known_false_positives: The jsp file names are static names used in current proof of concept code. =
|
||||
description: The following analytic is static indicators related to CVE-2022-22963,
|
||||
Spring4Shell. The 3 indicators provide an amount of fidelity that source IP is attemping
|
||||
to exploit a web shell on the destination. The filename and cmd are arbitrary in
|
||||
this exploitation. Java will write a JSP to disk and a process will spawn from Java
|
||||
based on the cmd passed. This is indicative of typical web shell activity.
|
||||
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url
|
||||
IN ("*tomcatwar.jsp*","*poc.jsp*","*shell.jsp*") by Web.http_user_agent Web.http_method,
|
||||
Web.url,Web.url_length Web.src, Web.dest sourcetype | `drop_dm_object_name("Web")`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `spring4shell_payload_url_request_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on Web traffic that include fields relavent for traffic into the `Web` datamodel.
|
||||
known_false_positives: The jsp file names are static names used in current proof of
|
||||
concept code. =
|
||||
references:
|
||||
- https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/
|
||||
- https://github.com/TheGejr/SpringShell
|
||||
@@ -70,3 +71,5 @@ tags:
|
||||
- Web.http_user_agent
|
||||
risk_score: 36
|
||||
security_domain: network
|
||||
supported_tas:
|
||||
- Splunk_TA_nginx
|
||||
|
||||
@@ -6,18 +6,19 @@ author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
datamodel:
|
||||
- Web
|
||||
description: The following analytic identifies the common URL requests used by a recent CVE - CVE-2022-22965, or Spring4Shell, to access a webshell on the remote webserver.
|
||||
The filename and cmd are arbitrary in this exploitation. Java will write a JSP to disk and a process will spawn from Java based on the cmd passed. This is indicative of typical web shell activity.
|
||||
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET")
|
||||
Web.url IN ("*.jsp?cmd=*","*j&cmd=*")
|
||||
by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest
|
||||
sourcetype
|
||||
| `drop_dm_object_name("Web")`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `web_jsp_request_via_url_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on Web traffic that include fields relavent for traffic into the `Web` datamodel.
|
||||
known_false_positives: False positives may be present with legitimate applications. Attempt to filter by dest IP or use Asset groups to restrict to servers.
|
||||
description: The following analytic identifies the common URL requests used by a recent
|
||||
CVE - CVE-2022-22965, or Spring4Shell, to access a webshell on the remote webserver.
|
||||
The filename and cmd are arbitrary in this exploitation. Java will write a JSP to
|
||||
disk and a process will spawn from Java based on the cmd passed. This is indicative
|
||||
of typical web shell activity.
|
||||
search: '| tstats count from datamodel=Web where Web.http_method IN ("GET") Web.url
|
||||
IN ("*.jsp?cmd=*","*j&cmd=*") by Web.http_user_agent Web.http_method, Web.url,Web.url_length
|
||||
Web.src, Web.dest sourcetype | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `web_jsp_request_via_url_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on Web traffic that include fields relavent for traffic into the `Web` datamodel.
|
||||
known_false_positives: False positives may be present with legitimate applications.
|
||||
Attempt to filter by dest IP or use Asset groups to restrict to servers.
|
||||
references:
|
||||
- https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/
|
||||
- https://github.com/TheGejr/SpringShell
|
||||
@@ -40,7 +41,8 @@ tags:
|
||||
impact: 90
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
message: A suspicious URL has been requested against $dest$ by $src$, related to web shell activity.
|
||||
message: A suspicious URL has been requested against $dest$ by $src$, related to
|
||||
web shell activity.
|
||||
mitre_attack_id:
|
||||
- T1505.003
|
||||
- T1505
|
||||
@@ -69,4 +71,6 @@ tags:
|
||||
- Web.dest
|
||||
- Web.http_user_agent
|
||||
risk_score: 72
|
||||
security_domain: network
|
||||
security_domain: network
|
||||
supported_tas:
|
||||
- Splunk_TA_nginx
|
||||
|
||||
@@ -1,317 +1,393 @@
|
||||
detection_name,cim_version,supported_tas,tas_with_cim_mapping
|
||||
abnormally_high_number_of_cloud_security_group_api_calls,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
|
||||
cloud_api_calls_from_previously_unseen_user_roles,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, splunk_ta_o365, Splunk_TA_box, Splunk_TA_infoblox, Splunk_TA_salesforce"
|
||||
cloud_compute_instance_created_in_previously_unused_region,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
|
||||
cloud_provisioning_from_previously_unseen_country,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
|
||||
cloud_compute_instance_created_with_previously_unseen_instance_type,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
|
||||
cloud_compute_instance_created_by_previously_unseen_user,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
|
||||
cloud_provisioning_from_previously_unseen_region,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
|
||||
abnormally_high_number_of_cloud_infrastructure_api_calls,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
|
||||
cloud_compute_instance_created_with_previously_unseen_image,5.0.0,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
|
||||
cloud_provisioning_from_previously_unseen_city,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_cisco-asa, Splunk_TA_infoblox, Splunk_TA_salesforce"
|
||||
cloud_provisioning_from_previously_unseen_ip_address,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce"
|
||||
cloud_instance_modified_with_previously_unseen_user,5.0.0,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_rsa_securid_cas, Splunk_TA_ossec, Splunk_TA_juniper, splunk_ta_o365, Splunk_TA_cyberark, Splunk_TA_box, Splunk_TA_salesforce"
|
||||
linux_setuid_using_chmod_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_folderoptions_windows_feature,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
anomalous_usage_of_7zip,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
enable_rdp_in_other_port_number,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
excessive_number_of_taskhost_processes,5.0.0,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
xsl_script_execution_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
rundll32_control_rundll_world_writable_directory,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_schedule_task,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
serviceprincipalnames_discovery_with_setspn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
allow_operation_with_consent_admin,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
windows_service_initiation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
spoolsv_writing_a_dll,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
dsquery_domain_discovery,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_possible_access_or_modification_of_sshd_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
secretdumps_offline_ntds_dumping_tool,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
attacker_tools_on_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows"
|
||||
domain_account_discovery_with_net_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
certutil_exe_certificate_extraction,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_html_help_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
prevent_automatic_repair_mode_using_bcdedit,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_possible_access_to_sudoers_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
get_domainpolicy_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
excessive_number_of_distinct_processes_created_in_windows_temp_folder,5.0.0,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
|
||||
disable_registry_tool,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
powershell_disable_security_monitoring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
svchost_exe_lolbas_execution_process_spawn,5.0.0,,Splunk_TA_microsoft_sysmon
|
||||
disable_defender_spynet_reporting,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
certutil_download_with_verifyctl_and_split_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_nirsoft_advancedrun,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
cmd_echo_pipe___escalation,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_number_of_service_control_start_as_disabled,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
windows_installutil_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_use_of_cmd_exe_to_launch_script_interpreters,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
suspicious_icedid_rundll32_cmdline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_service_stop_attempt,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_copy_on_system32,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
credential_dumping_via_symlink_to_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_searchprotocolhost_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_usage_of_net_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
permission_modification_using_takeown_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_at_application_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
reg_exe_manipulating_windows_services_registry_keys,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
logon_script_event_trigger_execution,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_possible_ssh_key_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
dump_lsass_via_procdump,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
getwmiobject_ds_computer_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
sdclt_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
hide_user_account_from_sign_in_screen,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
deleting_of_net_users,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
revil_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_psexec_with_accepteula_flag,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remote_process_instantiation_via_dcom_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
auto_admin_logon_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_doas_tool_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
modify_acl_permission_to_files_or_folder,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
getdomaingroup_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_amsi_through_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
wermgr_process_spawned_cmd_or_powershell_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_azurehound_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_product_spawning_rundll32_with_no_dll,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_exchange_web_shell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
time_provider_persistence_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
system_processes_run_from_unexpected_locations,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
scheduled_task_initiation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
sc_exe_manipulating_windows_services,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
disable_defender_submit_samples_consent_feature,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
ryuk_wake_on_lan_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
suspicious_msbuild_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_possible_access_to_credential_files,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
suspicious_wevtutil_usage,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
excessive_usage_of_cacls_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_task_manager,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
office_document_spawned_child_process_to_download,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
processes_launching_netsh,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_possible_append_command_to_at_allow_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
single_letter_process_on_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
|
||||
check_elevated_cmd_using_whoami,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
short_lived_windows_accounts,5.0.0,,"Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose, Splunk_TA_cyberark"
|
||||
possible_lateral_movement_powershell_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
schtasks_scheduling_job_on_remote_system,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
executables_or_script_creation_in_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
active_setup_registry_autostart,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
suspicious_rundll32_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
winword_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_regsvr32_register_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_install_kernel_module_using_modprobe_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
scheduled_task_creation_on_remote_endpoint_using_at,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_possible_append_command_to_profile_config_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
nishang_powershelltcponeline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_mshta_url_in_command_line,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_sudoers_tmp_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_service_restarted,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_defender_services,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
getwmiobject_ds_group_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
firewall_allowed_program_enable,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
office_application_spawn_regsvr32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_rundll32_inline_hta_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_gpupdate_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
extraction_of_registry_hives,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
powershell_start_bitstransfer,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_mshta_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_rundll32_application_control_bypass___setupapi,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
recursive_delete_of_directory_in_batch_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
get_aduserresultantpasswordpolicy_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
windows_dotnet_binary_in_non_standard_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
net_profiler_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disable_etw_through_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
remote_process_instantiation_via_winrm_and_winrs,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_product_spawning_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
execution_of_file_with_multiple_extensions,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows"
|
||||
remote_process_instantiation_via_winrm_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_process_file_path,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
any_powershell_downloadstring,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_change_file_owner_to_root,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
process_creating_lnk_file_in_suspicious_location,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
wbadmin_delete_system_backups,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_pkexec_privilege_escalation,5.0.0,,Splunk_TA_microsoft_sysmon
|
||||
disabling_controlpanel,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
attempt_to_stop_security_service,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excel_spawning_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
allow_inbound_traffic_by_firewall_rule_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
getdomaincomputer_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
malicious_powershell_process___execution_policy_bypass,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_defender_enhanced_notification,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
fodhelper_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_regsvr32_application_control_bypass,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_curl_download_to_suspicious_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remcos_client_registry_install_entry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_microsoft_workflow_compiler_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
bcdedit_failure_recovery_modification,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_service_file_created_in_systemd_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
slui_runas_elevated,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
batch_file_write_to_system32,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_dism_remove_defender,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_usage_of_taskkill,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
nltest_domain_trust_discovery,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
fsutil_zeroing_file,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
office_application_spawn_rundll32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
add_or_set_windows_defender_exclusion,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
bitsadmin_download_file,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
print_processor_registry_autostart,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_path_interception_by_creation_of_program_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
cmdline_tool_not_executed_in_cmd_shell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_mshta_inline_hta_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_rundll32_startw,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
script_execution_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
|
||||
slui_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
scheduled_task_deleted_or_created_via_cmd,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
allow_network_discovery_in_firewall,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_file_created_in_kernel_driver_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disable_logs_using_wevtutil,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
revil_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_sharphound_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
wmiprsve_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_file_creation_in_profile_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
services_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
regsvr32_with_known_silent_switch_cmdline,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_installutil_uninstall_option,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
deleting_shadow_copies,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
winhlp32_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disabling_firewall_with_netsh,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
elevated_group_discovery_with_net,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_setuid_using_setcap_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_preload_hijack_library_calls,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_installutil_in_non_standard_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
get_foresttrust_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_defender_exclusion_registry_entry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_adfind_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disabling_cmd_application,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
msmpeng_application_dll_side_loading,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
account_discovery_with_net_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_insert_kernel_module_using_insmod_utility,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
certutil_download_with_urlcache_and_split_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_msbuild_rename,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_mshta_child_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
set_default_powershell_execution_policy_to_unrestricted_or_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
uninstall_app_using_msiexec,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
execute_javascript_with_jscript_com_clsid,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
create_local_admin_accounts_using_net_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_uac_remote_restriction,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_doas_conf_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
creation_of_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_file_creation_in_init_boot_directory,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
windows_disableantispyware_reg,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disable_defender_mpengine_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
getwmiobject_ds_user_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disable_windows_app_hotkeys,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
dns_exfiltration_using_nslookup_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
clear_unallocated_sector_using_cipher_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_java_spawning_shell,5.0.0,,Splunk_TA_microsoft_sysmon
|
||||
disable_defender_blockatfirstseen_feature,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remote_process_instantiation_via_wmi_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regsvcs_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
get_domaintrust_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_installutil_credential_theft,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
elevated_group_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
registry_keys_used_for_persistence,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_rundll32_application_control_bypass___syssetup,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
ping_sleep_batch_command,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_processes_used_for_system_network_configuration_discovery,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
clop_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_product_spawning_certutil,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
regsvr32_silent_and_install_param_dll_loading,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
msbuild_suspicious_spawned_by_script_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
hiding_files_and_directories_with_attrib_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows"
|
||||
office_product_spawn_cmd_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
wsreset_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
certutil_with_decode_argument,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
allow_file_and_printing_sharing_in_firewall,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
system_information_discovery_detection,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR, Splunk_TA_cyberark_epm"
|
||||
malicious_powershell_process_with_obfuscation_techniques,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_add_files_in_known_crontab_directories,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
eventvwr_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
icacls_deny_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
usn_journal_deletion,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
remote_system_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_html_help_using_infotech_storage_handlers,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_security_logs_using_minint_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
sdelete_application_execution,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
curl_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
icacls_grant_command,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
winword_spawning_cmd,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
credential_dumping_via_copy_command_from_shadow_copy,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regasm_with_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
enable_wdigest_uselogoncredential_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
control_loading_from_world_writable_directory,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remote_process_instantiation_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_dllhost_no_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
spoolsv_spawning_rundll32,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
conti_common_exec_parameter,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
attempted_credential_dump_from_registry_via_reg_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
jscript_execution_using_cscript_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
bcdedit_command_back_to_normal_mode_boot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
rundll32_shimcache_flush,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
screensaver_event_trigger_execution,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
office_product_spawning_bitsadmin,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
change_default_file_association,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
wscript_or_cscript_suspicious_child_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
domain_controller_discovery_with_nltest,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_windows_behavior_monitoring,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
windows_curl_upload_to_remote_destination,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
unified_messaging_service_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_html_help_spawn_child_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regsvcs_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
linux_service_started_or_enabled,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
java_class_file_download_by_java_user_agent,5.0.0,,"Splunk_TA_citrix-netscaler, Splunk_TA_nginx, Splunk_TA_microsoft-iis, Splunk_TA_websense-cg, Splunk_TA_squid, Splunk_TA_haproxy, Splunk_TA_mcafee-wg, Splunk_TA_cisco-wsa"
|
||||
linux_at_allow_config_file_creation,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disable_defender_antivirus_registry,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_visudo_utility_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
schtasks_run_task_on_demand,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
schtasks_used_for_forcing_a_reboot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_raccine_scheduled_task_deletion,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
mshta_spawning_rundll32_or_regsvr32_process,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_attempt_to_disable_services,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
get_domainuser_with_powershell,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
suspicious_scheduled_task_from_public_directory,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
rundll32_with_no_command_line_arguments_with_network,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_service_creation_on_remote_endpoint,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_nopasswd_entry_in_sudoers_file,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
attempt_to_add_certificate_to_untrusted_store,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
process_kill_base_on_file_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
wsmprovhost_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
domain_account_discovery_with_wmic,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disabling_norun_windows_app,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
suspicious_rundll32_plugininit,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
file_with_samsam_extension,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
silentcleanup_uac_bypass,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
ntdsutil_export_ntds,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
disabling_systemrestore_in_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
vbscript_execution_using_wscript_app,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_spawning_control,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regasm_spawning_a_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
start_up_during_safe_mode_boot,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
office_product_spawning_mshta,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
change_to_safe_mode_with_network_config,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
potentially_malicious_code_on_commandline,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_rundll32_application_control_bypass___advpack,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
services_escalate_exe,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
wget_download_and_bash_execution,5.0.0,,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
remote_wmi_command_attempt,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
create_or_delete_windows_shares_using_net_exe,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
unload_sysmon_filter_driver,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
resize_shadowstorage_volume,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
wmic_xsl_execution_via_url,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_reg_exe_process,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
etw_registry_disabled,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
process_execution_via_wmi,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
samsam_test_file_write,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
impacket_lateral_movement_commandline_parameters,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
dump_lsass_via_comsvcs_dll,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
creation_of_shadow_copy_with_wmic_and_powershell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
overwriting_accessibility_binaries,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_ossec, Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, splunk_ta_o365, Splunk_TA_sophos, Splunk_TA_cyberark, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
add_defaultuser_and_password_in_registry,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
bits_job_persistence,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_rundll32_dllregisterserver,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
any_powershell_downloadfile,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
mmc_exe_lolbas_execution_process_spawn,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
w3wp_spawning_shell,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_sharphound_command_line_arguments,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon"
|
||||
detect_rclone_command_line_usage,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_msbuild_path,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disabling_net_user_account,5.0.0,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
shim_database_installation_with_suspicious_parameters,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_bit9-carbonblack, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR"
|
||||
dns_query_length_with_high_standard_deviation,5.0.0,Splunk_TA_microsoft_sysmon,"Splunk_TA_isc-bind, Splunk_TA_microsoft_sysmon, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox"
|
||||
cloud_compute_instance_created_in_previously_unused_region,5.0.1,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
|
||||
abnormally_high_number_of_cloud_security_group_api_calls,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
|
||||
abnormally_high_number_of_cloud_infrastructure_api_calls,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
|
||||
cloud_provisioning_from_previously_unseen_region,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
|
||||
cloud_provisioning_from_previously_unseen_city,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
|
||||
cloud_provisioning_from_previously_unseen_ip_address,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose"
|
||||
cloud_instance_modified_with_previously_unseen_user,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_ossec, Splunk_TA_citrix-netscaler, Splunk_TA_nix, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose"
|
||||
cloud_compute_instance_created_by_previously_unseen_user,5.0.1,Splunk_TA_aws-kinesis-firehose,Splunk_TA_aws-kinesis-firehose
|
||||
cloud_api_calls_from_previously_unseen_user_roles,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
|
||||
cloud_provisioning_from_previously_unseen_country,5.0.1,Splunk_TA_aws-kinesis-firehose,"Splunk_TA_juniper, Splunk_TA_citrix-netscaler, Splunk_TA_cyberark, Splunk_TA_salesforce, Splunk_TA_rsa_securid_cas, Splunk_TA_box, splunk_ta_o365, Splunk_TA_rsa-securid, Splunk_TA_cisco-asa, Splunk_TA_aws-kinesis-firehose, Splunk_TA_infoblox"
|
||||
spring4shell_payload_url_request,5.0.1,Splunk_TA_nginx,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
|
||||
log4shell_jndi_payload_injection_attempt,5.0.1,Splunk_TA_nginx,Splunk_TA_nginx
|
||||
vmware_workspace_one_freemarker_server_side_template_injection,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
|
||||
web_spring_cloud_function_functionrouter,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
|
||||
web_jsp_request_via_url,5.0.1,Splunk_TA_nginx,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
|
||||
print_processor_registry_autostart,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
dns_query_length_with_high_standard_deviation,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_isc-bind, Splunk_TA_CrowdStrike_FDR, Splunk_TA_infoblox"
|
||||
f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
|
||||
windows_service_initiation_on_remote_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regsvcs_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
process_kill_base_on_file_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
schtasks_scheduling_job_on_remote_system,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
shim_database_installation_with_suspicious_parameters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_firewall_with_netsh,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_binary_proxy_execution_mavinject_dll_injection,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
domain_controller_discovery_with_nltest,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_rundll32_application_control_bypass___syssetup,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_command_and_scripting_interpreter_path_traversal_exec,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
slui_runas_elevated,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_hide_notification_features_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
silentcleanup_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
deleting_shadow_copies,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
clop_common_exec_parameter,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_remote_service_rdpwinst_tool_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
wsreset_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_nirsoft_advancedrun,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
resize_shadowstorage_volume,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
attempted_credential_dump_from_registry_via_reg_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_process_file_path,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
slui_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_modify_registry_disable_windows_security_center_notif,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
registry_keys_for_creating_shim_databases,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
wermgr_process_spawned_cmd_or_powershell_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_obfuscated_files_or_information_base64_decode,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
windows_disableantispyware_reg,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
disabling_norun_windows_app,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
single_letter_process_on_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
|
||||
batch_file_write_to_system32,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_folderoptions_windows_feature,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_system_network_discovery,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_curl_upload_to_remote_destination,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_disable_lock_workstation_feature_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
wsmprovhost_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
winword_spawning_cmd,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
malicious_powershell_process___execution_policy_bypass,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
vbscript_execution_using_wscript_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
ntdsutil_export_ntds,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_system_shutdown_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_mshta_url_in_command_line,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
jscript_execution_using_cscript_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_remote_services_allow_remote_assistance,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
add_defaultuser_and_password_in_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_adfind_exe,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
fsutil_zeroing_file,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
detect_rclone_command_line_usage,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remote_process_instantiation_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_possible_append_command_to_profile_config_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_office_product_spawning_msdt,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
nishang_powershelltcponeline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_usage_of_net_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_sharphound_usage,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
dump_lsass_via_procdump,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
domain_account_discovery_with_net_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_disable_shutdown_button_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_modify_show_compress_color_and_info_tip_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
msbuild_suspicious_spawned_by_script_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_usage_of_taskkill,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_impair_defense_deny_security_software_with_applocker,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_raccine_scheduled_task_deletion,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_rundll32_startw,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_psexec_with_accepteula_flag,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
get_aduserresultantpasswordpolicy_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
allow_file_and_printing_sharing_in_firewall,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
eventvwr_uac_bypass,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
regsvr32_silent_and_install_param_dll_loading,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_valid_account_with_never_expires_password,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regsvcs_with_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
change_to_safe_mode_with_network_config,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
control_loading_from_world_writable_directory,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_scheduled_task_from_public_directory,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
cmd_echo_pipe___escalation,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_possible_append_command_to_at_allow_config_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
winhlp32_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_doas_conf_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_modify_registry_disable_toast_notifications,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
permission_modification_using_takeown_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
detect_rundll32_application_control_bypass___advpack,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
create_or_delete_windows_shares_using_net_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
anomalous_usage_of_7zip,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_install_kernel_module_using_modprobe_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_remote_assistance_spawning_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
registry_keys_used_for_privilege_escalation,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
windows_command_shell_dcrat_forkbomb_payload,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
domain_account_discovery_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_change_file_owner_to_root,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
executables_or_script_creation_in_suspicious_path,5.0.1,,"Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
suspicious_copy_on_system32,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
certutil_download_with_urlcache_and_split_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_registry_modification_for_safe_mode_persistence,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
hiding_files_and_directories_with_attrib_exe,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
enable_rdp_in_other_port_number,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
dsquery_domain_discovery,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
credential_dumping_via_copy_command_from_shadow_copy,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
get_foresttrust_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
malicious_powershell_process_with_obfuscation_techniques,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
creation_of_shadow_copy,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
any_powershell_downloadstring,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
bcdedit_command_back_to_normal_mode_boot,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_deleted_registry_by_a_non_critical_process_file_path,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
detect_html_help_url_in_command_line,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_service_creation_using_registry_entry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
dump_lsass_via_comsvcs_dll,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_high_frequency_of_file_deletion_in_boot_folder,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_curl_download_to_suspicious_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
powershell_disable_security_monitoring,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
icacls_grant_command,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
nltest_domain_trust_discovery,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
disable_amsi_through_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
detect_mshta_inline_hta_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_rasautou_dll_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
mmc_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
recursive_delete_of_directory_in_batch_cmd,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
revil_registry_entry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_file_created_in_kernel_driver_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_system_time_discovery_w32tm_delay,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
system_information_discovery_detection,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
|
||||
uninstall_app_using_msiexec,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
detect_rundll32_application_control_bypass___setupapi,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
w3wp_spawning_shell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_registry_delete_task_sd,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
powershell_start_bitstransfer,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regasm_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
hide_user_account_from_sign_in_screen,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
get_domaintrust_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
samsam_test_file_write,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
|
||||
prevent_automatic_repair_mode_using_bcdedit,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
detect_regsvr32_application_control_bypass,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
schtasks_used_for_forcing_a_reboot,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_deletion_of_services,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
svchost_exe_lolbas_execution_process_spawn,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
windows_installutil_uninstall_option,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
account_discovery_with_net_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disabling_systemrestore_in_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_possible_ssh_key_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
linux_nopasswd_entry_in_sudoers_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
create_local_admin_accounts_using_net_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_processes_used_for_system_network_configuration_discovery,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
processes_launching_netsh,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
excessive_distinct_processes_from_windows_temp,5.0.1,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
|
||||
wget_download_and_bash_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
process_creating_lnk_file_in_suspicious_location,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
bcdedit_failure_recovery_modification,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_remote_access_software_rms_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
services_escalate_exe,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
scheduled_task_deleted_or_created_via_cmd,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
wscript_or_cscript_suspicious_child_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_at_application_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_indirect_command_execution_via_forfiles,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_disable_logoff_button_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
sdclt_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
clear_unallocated_sector_using_cipher_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
usn_journal_deletion,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
certutil_with_decode_argument,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_service_restarted,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
credential_dumping_via_symlink_to_shadow_copy,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
conti_common_exec_parameter,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
fodhelper_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
disable_schedule_task,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_system_reboot_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_azurehound_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remote_wmi_command_attempt,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_file_creation_in_init_boot_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
active_setup_registry_autostart,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_possible_access_to_credential_files,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_controlpanel,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
windows_impair_defense_delete_win_defender_profile_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
possible_lateral_movement_powershell_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
dns_exfiltration_using_nslookup_app,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_path_interception_by_creation_of_program_exe,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_visudo_utility_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
elevated_group_discovery_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_regsvr32_register_suspicious_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_rundll32_plugininit,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
bits_job_persistence,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
sc_exe_manipulating_windows_services,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
shim_database_file_creation,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_ossec, Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
excessive_number_of_taskhost_processes,5.0.1,Splunk_TA_windows,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
scheduled_task_initiation_on_remote_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
bitsadmin_download_file,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_product_spawning_rundll32_with_no_dll,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_registry_tool,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_decode_base64_to_shell,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
curl_download_and_bash_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
elevated_group_discovery_with_net,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disabling_cmd_application,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_deletion_of_ssl_certificate,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
short_lived_windows_accounts,5.0.1,,"Splunk_TA_cyberark, Splunk_TA_microsoft-cloudservices, Splunk_TA_rsa-securid, Splunk_TA_aws-kinesis-firehose"
|
||||
spoolsv_writing_a_dll,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
get_domainuser_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
ryuk_wake_on_lan_command,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
unified_messaging_service_spawning_a_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
getwmiobject_ds_user_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
office_application_spawn_regsvr32_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_etw_through_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
rundll32_with_no_command_line_arguments_with_network,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_product_spawning_mshta,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_number_of_service_control_start_as_disabled,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_odbcconf_load_response_file,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
certutil_download_with_verifyctl_and_split_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_deletion_of_cron_jobs,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
suspicious_msbuild_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
execution_of_file_with_multiple_extensions,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_impair_defenses_disable_win_defender_auto_logging,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_kernel_module_enumeration,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
office_product_spawn_cmd_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_disable_memory_crash_dump,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
serviceprincipalnames_discovery_with_setspn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_doas_tool_execution,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
suspicious_rundll32_dllregisterserver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_microsoft_workflow_compiler_usage,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_usage_of_cacls_app,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_iptables_firewall_modification,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
remote_process_instantiation_via_winrm_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
getdomaincomputer_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_icedid_rundll32_cmdline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_java_spawning_shell,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
windows_schtasks_create_run_as_system,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
firewall_allowed_program_enable,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
suspicious_gpupdate_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_registry_certificate_added,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
suspicious_mshta_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
revil_common_exec_parameter,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
wmic_xsl_execution_via_url,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
potentially_malicious_code_on_commandline,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_ssh_remote_services_script_execute,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
mimikatz_passtheticket_commandline_parameters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_modify_registry_regedit_silent_reg_import,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
monitor_registry_keys_for_print_monitors,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
cmdline_tool_not_executed_in_cmd_shell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_dism_remove_defender,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_html_help_using_infotech_storage_handlers,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_html_help_spawn_child_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_rundll32_inline_hta_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
time_provider_persistence_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
attacker_tools_on_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_service_stop_by_deletion,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
excessive_service_stop_attempt,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
icacls_deny_command,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_deleting_critical_directory_using_rm_command,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
disable_windows_behavior_monitoring,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
script_execution_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
|
||||
secretdumps_offline_ntds_dumping_tool,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
remote_process_instantiation_via_winrm_and_winrs,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_msbuild_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_mshta_child_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_clipboard_data_copy,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
rubeus_command_line_parameters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
set_default_powershell_execution_policy_to_unrestricted_or_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
linux_disable_services,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
unload_sysmon_filter_driver,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
process_execution_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
disabling_task_manager,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
certutil_exe_certificate_extraction,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_disable_windows_group_policy_features_through_registry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
file_with_samsam_extension,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
|
||||
rundll32_control_rundll_world_writable_directory,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
getdomaingroup_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
change_default_file_association,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
rundll32_lockworkstation,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
ping_sleep_batch_command,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disabling_remote_user_account_control,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_sudoers_tmp_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
overwriting_accessibility_binaries,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_ossec, Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
|
||||
rundll_loading_dll_by_ordinal,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_possible_access_or_modification_of_sshd_config_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
system_processes_run_from_unexpected_locations,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
spoolsv_spawning_rundll32,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_security_account_manager_stopped,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_cyberark_epm, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_process_with_namedpipe_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
wbadmin_delete_system_backups,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
xsl_script_execution_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_add_files_in_known_crontab_directories,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
extraction_of_registry_hives,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_rundll32_with_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_mof_event_triggered_execution_via_wmi,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
registry_keys_used_for_persistence,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
windows_modify_registry_disable_win_defender_raw_write_notif,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
scheduled_task_creation_on_remote_endpoint_using_at,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
excessive_attempt_to_disable_services,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_indirect_command_execution_via_pcalua,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
windows_dotnet_binary_in_non_standard_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_searchprotocolhost_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_msiexec_unregister_dllregisterserver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
attempt_to_stop_security_service,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_installutil_in_non_standard_path,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
java_class_file_download_by_java_user_agent,5.0.1,,"Splunk_TA_squid, Splunk_TA_citrix-netscaler, Splunk_TA_cisco-wsa, Splunk_TA_mcafee-wg, Splunk_TA_haproxy, Splunk_TA_websense-cg, Splunk_TA_microsoft-iis, Splunk_TA_nginx"
|
||||
linux_deletion_of_init_daemon_script,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
getwmiobject_ds_computer_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_stop_services,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
net_profiler_uac_bypass,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_msiexec_spawn_discovery_command,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_ssh_authorized_keys_modification,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
windows_disable_change_password_through_registry,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
windows_remote_services_rdp_enable,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_at_allow_config_file_creation,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
excel_spawning_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
logon_script_event_trigger_execution,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
windows_processes_killed_by_industroyer2_malware,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
impacket_lateral_movement_commandline_parameters,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_regasm_with_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_application_spawn_rundll32_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_installutil_url_in_command_line,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
allow_operation_with_consent_admin,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
linux_preload_hijack_library_calls,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_installutil_credential_theft,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_service_create_kernel_mode_driver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disabling_net_user_account,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_exchange_web_shell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_system_logoff_commandline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_msiexec_remote_download,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
detect_use_of_cmd_exe_to_launch_script_interpreters,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
regsvr32_with_known_silent_switch_cmdline,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_pkexec_privilege_escalation,5.0.1,,Splunk_TA_microsoft_sysmon
|
||||
reg_exe_manipulating_windows_services_registry_keys,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
linux_insert_kernel_module_using_insmod_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
add_or_set_windows_defender_exclusion,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_linux_discovery_commands,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
office_product_spawning_wmic,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
disable_logs_using_wevtutil,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
deleting_of_net_users,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
sdelete_application_execution,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
remote_process_instantiation_via_wmi_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
rundll32_shimcache_flush,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_writes_to_windows_recycle_bin,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
modify_acl_permission_to_files_or_folder,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_remote_services_allow_rdp_in_firewall,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
any_powershell_downloadfile,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
schtasks_run_task_on_demand,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
remote_system_discovery_with_wmic,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_reg_exe_process,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_msiexec_dllregisterserver,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_possible_access_to_sudoers_file,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_modify_registry_disabling_wer_settings,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
remote_process_instantiation_via_dcom_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
screensaver_event_trigger_execution,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
get_domainpolicy_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
msmpeng_application_dll_side_loading,5.0.1,,"Splunk_TA_bit9-carbonblack, Splunk_TA_CrowdStrike_FDR"
|
||||
services_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
auto_admin_logon_registry_entry,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
ryuk_test_files_detected,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_nix, Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_cyberark, Splunk_TA_sophos, Splunk_TA_windows, splunk_ta_o365, Splunk_TA_CrowdStrike_FDR"
|
||||
check_elevated_cmd_using_whoami,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
creation_of_shadow_copy_with_wmic_and_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_shred_overwrite_command,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_file_without_extension_in_critical_folder,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_dd_file_overwrite,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
disable_windows_app_hotkeys,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
getwmiobject_ds_group_with_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
office_spawning_control,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
execute_javascript_with_jscript_com_clsid,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
mshta_spawning_rundll32_or_regsvr32_process,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
allow_network_discovery_in_firewall,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_dllhost_no_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_high_frequency_of_file_deletion_in_etc_folder,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
winword_spawning_powershell,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_modify_registry_disallow_windows_app,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
detect_sharphound_command_line_arguments,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
wmiprsve_exe_lolbas_execution_process_spawn,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
suspicious_wevtutil_usage,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_execute_arbitrary_commands_with_msdt,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_service_started_or_enabled,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
office_document_spawned_child_process_to_download,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
windows_odbcconf_load_dll,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
attempt_to_add_certificate_to_untrusted_store,5.0.1,Splunk_TA_microsoft_sysmon,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows"
|
||||
linux_setuid_using_setcap_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
windows_modify_registry_suppress_win_defender_notif,5.0.1,,Splunk_TA_bit9-carbonblack
|
||||
linux_setuid_using_chmod_utility,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack, Splunk_TA_windows, Splunk_TA_CrowdStrike_FDR"
|
||||
office_product_spawning_certutil,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_file_creation_in_profile_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
windows_service_creation_on_remote_endpoint,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_account_manipulation_of_ssh_config_and_keys,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
office_product_spawning_bitsadmin,5.0.1,Splunk_TA_microsoft_sysmon,Splunk_TA_microsoft_sysmon
|
||||
linux_service_file_created_in_systemd_directory,5.0.1,,"Splunk_TA_microsoft_sysmon, Splunk_TA_bit9-carbonblack"
|
||||
|
||||
|
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user