updating detection

This commit is contained in:
Bhavin Patel
2024-10-09 17:33:20 -07:00
parent 4702243b86
commit e95c2d274f
+16 -23
View File
@@ -5,29 +5,19 @@ date: '2024-10-09'
author: Jose Hernandez, Bhavin Patel, Splunk
status: production
type: TTP
description: 'The following analytic identifies the execution of
specific command-line arguments that are associated with AdFind.exe, a command-line
tool for AD administration and management. AdFind can be misused by malicious actors to gather sensitive information from Active Directory, such as user accounts, group memberships, and network configurations. This information can be leveraged to identify high-value targets, escalate privileges, or plan further attacks within an organization's network. Unauthorized use of AdFind can lead to data breaches and compromise the security of the entire Active Directory environment. It leverages data from Endpoint Detection
and Response (EDR) agents, focusing on process names, command-line arguments, and
parent processes. This activity is significant because `adfind.exe` is a powerful
tool often used by threat actors like Wizard Spider and FIN6 to gather sensitive AD
information. If confirmed malicious, this activity could allow attackers to map the
AD environment, facilitating further attacks such as privilege escalation or lateral
movement.'
description: 'The following analytic identifies the execution of `adfind.exe` with
specific command-line arguments related to Active Directory queries. It leverages
data from Endpoint Detection and Response (EDR) agents, focusing on process names,
command-line arguments, and parent processes. This activity is significant because
`adfind.exe` is a powerful tool often used by threat actors like Wizard Spider and
FIN6 to gather sensitive AD information. If confirmed malicious, this activity could
allow attackers to map the AD environment, facilitating further attacks such as
privilege escalation or lateral movement.'
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where ((Processes.process="* -f *"
OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="*
-gcb *" OR Processes.process="* -sc *" )) OR ((Processes.process="*trustdmp*" OR Processes.process="*dclist*")) by Processes.dest Processes.user Processes.process_name
Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_adfind_exe_filter`
| `windows_adfind_exe_filter`'
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((Processes.process="* -f *" OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="*-gcb *" OR Processes.process="* -sc *" )) OR ((Processes.process="*trustdmp*" OR Processes.process="*dclist*")) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_adfind_exe_filter`| `windows_adfind_exe_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
@@ -56,6 +46,13 @@ tags:
confidence: 50
impact: 50
message: Windows AdFind Exe detected with command-line arguments associated with Active Directory queries on machine - [dest]
atomic_guid:
- 736b4f53-f400-4c22-855d-1a6b5a551600
- b95fd967-4e62-4109-b48d-265edfd28c3a
- e1ec8d20-509a-4b9a-b820-06c9b2da8eb7
- 5e2938fb-f919-47b6-8b29-2f6a1f718e99
- abf00f6c-9983-4d9a-afbc-6b1c6c6448e1
- 51a98f96-0269-4e09-a10f-e307779a8b05
mitre_attack_id:
- T1018
observable:
@@ -63,10 +60,6 @@ tags:
type: User
role:
- Victim
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security