Deprecating two detections that identified all rundll32 executions.
Added linux pkexec pwnkit detection.
This commit is contained in:
mhaag-spl
2022-02-01 09:52:52 -07:00
parent 14c145c133
commit e8dd9051bc
6 changed files with 92 additions and 27 deletions
@@ -1,12 +1,12 @@
name: Suspicious Rundll32 Rename
id: 7360137f-abad-473e-8189-acbdaa34d114
version: 3
date: '2021-02-04'
version: 4
date: '2022-02-01'
author: Michael Haag, Splunk
type: Hunting
datamodel:
- Endpoint
description: The following analytic identifies renamed instances of rundll32.exe executing.
description: The following hunting analytic identifies renamed instances of rundll32.exe executing.
rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During
investigation, validate it is the legitimate rundll32.exe executing and what script
content it is loading. This query relies on the original filename or internal name
@@ -0,0 +1,77 @@
name: Linux pkexec Privilege Escalation
id: 03e22c1c-8086-11ec-ac2e-acde48001122
version: 1
date: '2022-01-28'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: 'The following analytic identifies `pkexec` spawning with no command-line arguments. A vulnerability in Polkit''s pkexec component identified as CVE-2021-4034 (PwnKit) which is present in the default configuration of all major Linux distributions and can be exploited to gain full root privileges on the system.'
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=pkexec by _time Processes.dest Processes.process_id Processes.parent_process_name Processes.process_name Processes.process Processes.process_path
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| regex process="(^.{1}$)"
| `linux_pkexec_privilege_escalation_filter`'
how_to_implement: 'Depending on the EDR product in use, there are multiple ways to "null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"` or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux was utilized.
To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.'
known_false_positives: False positives may be present, filter as needed.
references:
- https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/
- https://linux.die.net/man/1/pkexec
- https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/
- https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct
tags:
cve:
- CVE-2021-4034
analytic_story:
- Linux Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1068
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
security_domain: endpoint
impact: 80
confidence: 70
# (impact * confidence)/100
risk_score: 56
context:
- Source:Endpoint
- Stage:Defense Evasion
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit pkexec.
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Parent Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
@@ -0,0 +1,12 @@
name: Linux pkexec Privilege Escalation Unit Test
tests:
- name: Linux pkexec Privilege Escalation
file: endpoint/linux_pkexec_privilege_escalation.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: linux-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/pkexec/linux-sysmon.log
source: Syslog:Linux-Sysmon/Operational
sourcetype: sysmon_linux
@@ -1,12 +0,0 @@
name: RunDLL Loading DLL By Ordinal Unit Test
tests:
- name: RunDLL Loading DLL By Ordinal
file: endpoint/rundll_loading_dll_by_ordinal.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -1,12 +0,0 @@
name: Suspicious rundll32 rename unit test
tests:
- name: Detect Renamed rundll32.exe Rename
file: endpoint/suspicious_rundll32_rename.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog