From e8dd9051bcdfc8a2a33e0e43393ef0ebb95e2365 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 1 Feb 2022 09:52:52 -0700 Subject: [PATCH] pkexec Deprecating two detections that identified all rundll32 executions. Added linux pkexec pwnkit detection. --- .../rundll_loading_dll_by_ordinal.yml | 0 .../suspicious_rundll32_rename.yml | 6 +- .../linux_pkexec_privilege_escalation.yml | 77 +++++++++++++++++++ ...linux_pkexec_privilege_escalation.test.yml | 12 +++ .../rundll_loading_dll_by_ordinal.test.yml | 12 --- .../suspicious_rundll32_rename.test.yml | 12 --- 6 files changed, 92 insertions(+), 27 deletions(-) rename detections/{endpoint => deprecated}/rundll_loading_dll_by_ordinal.yml (100%) rename detections/{endpoint => deprecated}/suspicious_rundll32_rename.yml (95%) create mode 100644 detections/endpoint/linux_pkexec_privilege_escalation.yml create mode 100644 tests/endpoint/linux_pkexec_privilege_escalation.test.yml delete mode 100644 tests/endpoint/rundll_loading_dll_by_ordinal.test.yml delete mode 100644 tests/endpoint/suspicious_rundll32_rename.test.yml diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/deprecated/rundll_loading_dll_by_ordinal.yml similarity index 100% rename from detections/endpoint/rundll_loading_dll_by_ordinal.yml rename to detections/deprecated/rundll_loading_dll_by_ordinal.yml diff --git a/detections/endpoint/suspicious_rundll32_rename.yml b/detections/deprecated/suspicious_rundll32_rename.yml similarity index 95% rename from detections/endpoint/suspicious_rundll32_rename.yml rename to detections/deprecated/suspicious_rundll32_rename.yml index 459457a7d6..7fdc4f6525 100644 --- a/detections/endpoint/suspicious_rundll32_rename.yml +++ b/detections/deprecated/suspicious_rundll32_rename.yml @@ -1,12 +1,12 @@ name: Suspicious Rundll32 Rename id: 7360137f-abad-473e-8189-acbdaa34d114 -version: 3 -date: '2021-02-04' +version: 4 +date: '2022-02-01' author: Michael Haag, Splunk type: Hunting datamodel: - Endpoint -description: The following analytic identifies renamed instances of rundll32.exe executing. +description: The following hunting analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the original filename or internal name diff --git a/detections/endpoint/linux_pkexec_privilege_escalation.yml b/detections/endpoint/linux_pkexec_privilege_escalation.yml new file mode 100644 index 0000000000..ab911111a3 --- /dev/null +++ b/detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -0,0 +1,77 @@ +name: Linux pkexec Privilege Escalation +id: 03e22c1c-8086-11ec-ac2e-acde48001122 +version: 1 +date: '2022-01-28' +author: Michael Haag, Splunk +type: TTP +datamodel: + - Endpoint +description: 'The following analytic identifies `pkexec` spawning with no command-line arguments. A vulnerability in Polkit''s pkexec component identified as CVE-2021-4034 (PwnKit) which is present in the default configuration of all major Linux distributions and can be exploited to gain full root privileges on the system.' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=pkexec by _time Processes.dest Processes.process_id Processes.parent_process_name Processes.process_name Processes.process Processes.process_path + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | regex process="(^.{1}$)" + | `linux_pkexec_privilege_escalation_filter`' +how_to_implement: 'Depending on the EDR product in use, there are multiple ways to "null" the command-line field, Processes.process. Two that may be useful `process="(^.{0}$)"` or `| where isnull(process)`. To generate data for this behavior, Sysmon for Linux was utilized. + To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.' +known_false_positives: False positives may be present, filter as needed. +references: + - https://www.reddit.com/r/crowdstrike/comments/sdfeig/20220126_cool_query_friday_hunting_pwnkit_local/ + - https://linux.die.net/man/1/pkexec + - https://www.bleepingcomputer.com/news/security/linux-system-service-bug-gives-root-on-all-major-distros-exploit-released/ + - https://access.redhat.com/security/security-updates/#/?q=polkit&p=1&sort=portal_publication_date%20desc&rows=10&portal_advisory_type=Security%20Advisory&documentKind=PortalProduct +tags: + cve: + - CVE-2021-4034 + analytic_story: + - Linux Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/zoom_child_process/linux-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1068 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 80 + confidence: 70 + # (impact * confidence)/100 + risk_score: 56 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ related to a local privilege escalation in polkit pkexec. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/tests/endpoint/linux_pkexec_privilege_escalation.test.yml b/tests/endpoint/linux_pkexec_privilege_escalation.test.yml new file mode 100644 index 0000000000..13f788f251 --- /dev/null +++ b/tests/endpoint/linux_pkexec_privilege_escalation.test.yml @@ -0,0 +1,12 @@ +name: Linux pkexec Privilege Escalation Unit Test +tests: +- name: Linux pkexec Privilege Escalation + file: endpoint/linux_pkexec_privilege_escalation.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: linux-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/pkexec/linux-sysmon.log + source: Syslog:Linux-Sysmon/Operational + sourcetype: sysmon_linux \ No newline at end of file diff --git a/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml b/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml deleted file mode 100644 index 713662f1ea..0000000000 --- a/tests/endpoint/rundll_loading_dll_by_ordinal.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: RunDLL Loading DLL By Ordinal Unit Test -tests: -- name: RunDLL Loading DLL By Ordinal - file: endpoint/rundll_loading_dll_by_ordinal.yml - pass_condition: '| stats count | where count > 0' - earliest_time: '-24h' - latest_time: 'now' - attack_data: - - file_name: windows-sysmon.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog diff --git a/tests/endpoint/suspicious_rundll32_rename.test.yml b/tests/endpoint/suspicious_rundll32_rename.test.yml deleted file mode 100644 index 67a20e4bc5..0000000000 --- a/tests/endpoint/suspicious_rundll32_rename.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Suspicious rundll32 rename unit test -tests: -- name: Detect Renamed rundll32.exe Rename - file: endpoint/suspicious_rundll32_rename.yml - pass_condition: '| stats count | where count > 0' - earliest_time: '-24h' - latest_time: 'now' - attack_data: - - file_name: windows-sysmon.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog \ No newline at end of file