mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating detection
This commit is contained in:
@@ -5,29 +5,19 @@ date: '2024-10-09'
|
||||
author: Jose Hernandez, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: 'The following analytic identifies the execution of
|
||||
specific command-line arguments that are associated with AdFind.exe, a command-line
|
||||
tool for AD administration and management. AdFind can be misused by malicious actors to gather sensitive information from Active Directory, such as user accounts, group memberships, and network configurations. This information can be leveraged to identify high-value targets, escalate privileges, or plan further attacks within an organization's network. Unauthorized use of AdFind can lead to data breaches and compromise the security of the entire Active Directory environment. It leverages data from Endpoint Detection
|
||||
and Response (EDR) agents, focusing on process names, command-line arguments, and
|
||||
parent processes. This activity is significant because `adfind.exe` is a powerful
|
||||
tool often used by threat actors like Wizard Spider and FIN6 to gather sensitive AD
|
||||
information. If confirmed malicious, this activity could allow attackers to map the
|
||||
AD environment, facilitating further attacks such as privilege escalation or lateral
|
||||
movement.'
|
||||
description: 'The following analytic identifies the execution of `adfind.exe` with
|
||||
specific command-line arguments related to Active Directory queries. It leverages
|
||||
data from Endpoint Detection and Response (EDR) agents, focusing on process names,
|
||||
command-line arguments, and parent processes. This activity is significant because
|
||||
`adfind.exe` is a powerful tool often used by threat actors like Wizard Spider and
|
||||
FIN6 to gather sensitive AD information. If confirmed malicious, this activity could
|
||||
allow attackers to map the AD environment, facilitating further attacks such as
|
||||
privilege escalation or lateral movement.'
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
- Windows Event Log Security 4688
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where ((Processes.process="* -f *"
|
||||
OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="*
|
||||
-gcb *" OR Processes.process="* -sc *" )) OR ((Processes.process="*trustdmp*" OR Processes.process="*dclist*")) by Processes.dest Processes.user Processes.process_name
|
||||
Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `windows_adfind_exe_filter`
|
||||
| `windows_adfind_exe_filter`'
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((Processes.process="* -f *" OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="*-gcb *" OR Processes.process="* -sc *" )) OR ((Processes.process="*trustdmp*" OR Processes.process="*dclist*")) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_adfind_exe_filter`| `windows_adfind_exe_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
and Response (EDR) agents. These agents are designed to provide security-related
|
||||
telemetry from the endpoints where the agent is installed. To implement this search,
|
||||
@@ -56,6 +46,13 @@ tags:
|
||||
confidence: 50
|
||||
impact: 50
|
||||
message: Windows AdFind Exe detected with command-line arguments associated with Active Directory queries on machine - [dest]
|
||||
atomic_guid:
|
||||
- 736b4f53-f400-4c22-855d-1a6b5a551600
|
||||
- b95fd967-4e62-4109-b48d-265edfd28c3a
|
||||
- e1ec8d20-509a-4b9a-b820-06c9b2da8eb7
|
||||
- 5e2938fb-f919-47b6-8b29-2f6a1f718e99
|
||||
- abf00f6c-9983-4d9a-afbc-6b1c6c6448e1
|
||||
- 51a98f96-0269-4e09-a10f-e307779a8b05
|
||||
mitre_attack_id:
|
||||
- T1018
|
||||
observable:
|
||||
@@ -63,10 +60,6 @@ tags:
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
Reference in New Issue
Block a user