From e95c2d274fbf0b24cdee70cf270559a4e3350149 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Wed, 9 Oct 2024 17:33:20 -0700 Subject: [PATCH] updating detection --- detections/endpoint/windows_adfind_exe.yml | 39 +++++++++------------- 1 file changed, 16 insertions(+), 23 deletions(-) diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index b92855ac49..73869ab1f4 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -5,29 +5,19 @@ date: '2024-10-09' author: Jose Hernandez, Bhavin Patel, Splunk status: production type: TTP -description: 'The following analytic identifies the execution of - specific command-line arguments that are associated with AdFind.exe, a command-line - tool for AD administration and management. AdFind can be misused by malicious actors to gather sensitive information from Active Directory, such as user accounts, group memberships, and network configurations. This information can be leveraged to identify high-value targets, escalate privileges, or plan further attacks within an organization's network. Unauthorized use of AdFind can lead to data breaches and compromise the security of the entire Active Directory environment. It leverages data from Endpoint Detection - and Response (EDR) agents, focusing on process names, command-line arguments, and - parent processes. This activity is significant because `adfind.exe` is a powerful - tool often used by threat actors like Wizard Spider and FIN6 to gather sensitive AD - information. If confirmed malicious, this activity could allow attackers to map the - AD environment, facilitating further attacks such as privilege escalation or lateral - movement.' +description: 'The following analytic identifies the execution of `adfind.exe` with + specific command-line arguments related to Active Directory queries. It leverages + data from Endpoint Detection and Response (EDR) agents, focusing on process names, + command-line arguments, and parent processes. This activity is significant because + `adfind.exe` is a powerful tool often used by threat actors like Wizard Spider and + FIN6 to gather sensitive AD information. If confirmed malicious, this activity could + allow attackers to map the AD environment, facilitating further attacks such as + privilege escalation or lateral movement.' data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where ((Processes.process="* -f *" - OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="* - -gcb *" OR Processes.process="* -sc *" )) OR ((Processes.process="*trustdmp*" OR Processes.process="*dclist*")) by Processes.dest Processes.user Processes.process_name - Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `windows_adfind_exe_filter` - | `windows_adfind_exe_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where ((Processes.process="* -f *" OR Processes.process="* -b *") AND (Processes.process=*objectcategory* OR Processes.process="*-gcb *" OR Processes.process="* -sc *" )) OR ((Processes.process="*trustdmp*" OR Processes.process="*dclist*")) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_adfind_exe_filter`| `windows_adfind_exe_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -56,6 +46,13 @@ tags: confidence: 50 impact: 50 message: Windows AdFind Exe detected with command-line arguments associated with Active Directory queries on machine - [dest] + atomic_guid: + - 736b4f53-f400-4c22-855d-1a6b5a551600 + - b95fd967-4e62-4109-b48d-265edfd28c3a + - e1ec8d20-509a-4b9a-b820-06c9b2da8eb7 + - 5e2938fb-f919-47b6-8b29-2f6a1f718e99 + - abf00f6c-9983-4d9a-afbc-6b1c6c6448e1 + - 51a98f96-0269-4e09-a10f-e307779a8b05 mitre_attack_id: - T1018 observable: @@ -63,10 +60,6 @@ tags: type: User role: - Victim - - name: dest - type: Endpoint - role: - - Victim product: - Splunk Enterprise - Splunk Enterprise Security