mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Anomalous usage of 7zip
|
||||
id: 9364ee8e-a39a-11eb-8f1d-acde48001122
|
||||
version: 1
|
||||
date: '2021-04-22'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- NOBELIUM Group
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Attempt To Stop Security Service
|
||||
id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
|
||||
version: 4
|
||||
date: '2023-04-14'
|
||||
date: '2023-06-13'
|
||||
author: Rico Valdez, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,11 +29,12 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Azorult
|
||||
- Trickbot
|
||||
- WhisperGate
|
||||
- Graceful Wipe Out Attack
|
||||
- Disabling Security Tools
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Azorult
|
||||
- Trickbot
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 40
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: CMD Echo Pipe - Escalation
|
||||
id: eb277ba0-b96b-11eb-b00e-acde48001122
|
||||
version: 2
|
||||
date: '2021-05-20'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Cobalt Strike Named Pipes
|
||||
id: 5876d429-0240-4709-8b93-ea8330b411b5
|
||||
version: 2
|
||||
date: '2022-05-16'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -41,10 +41,11 @@ references:
|
||||
- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Trickbot
|
||||
- DarkSide Ransomware
|
||||
- LockBit Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Cobalt Strike
|
||||
- DarkSide Ransomware
|
||||
- Trickbot
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Deleting Of Net Users
|
||||
id: 1c8c6f66-acce-11eb-aafb-acde48001122
|
||||
version: 2
|
||||
date: '2021-05-04'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Regsvr32 Application Control Bypass
|
||||
id: 070e9b80-6252-11eb-ae93-0242ac130002
|
||||
version: 2
|
||||
date: '2021-01-28'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,9 +37,10 @@ references:
|
||||
- https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Regsvr32 Activity
|
||||
- Cobalt Strike
|
||||
- Living Off The Land
|
||||
- Suspicious Regsvr32 Activity
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: DLLHost with no Command Line Arguments with Network
|
||||
id: f1c07594-a141-11eb-8407-acde48001122
|
||||
version: 4
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Steven Dick, Michael Haag, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -34,6 +34,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Domain Account Discovery With Net App
|
||||
id: 98f6a534-04c2-11ec-96b2-acde48001122
|
||||
version: 1
|
||||
date: '2021-08-24'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Domain Group Discovery With Net
|
||||
id: f2f14ac7-fa81-471a-80d5-7eb65c3c7349
|
||||
version: 1
|
||||
date: '2021-08-25'
|
||||
date: '2023-06-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -25,9 +25,10 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1069/002/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Windows Post-Exploitation
|
||||
- Active Directory Discovery
|
||||
- Prestige Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Excessive Usage Of Net App
|
||||
id: 45e52536-ae42-11eb-b5c6-acde48001122
|
||||
version: 2
|
||||
date: '2021-05-06'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -27,11 +27,12 @@ references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Ransomware
|
||||
- Azorult
|
||||
- Windows Post-Exploitation
|
||||
- Prestige Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- XMRig
|
||||
- Windows Post-Exploitation
|
||||
- Azorult
|
||||
- Ransomware
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 40
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Executable File Written in Administrative SMB Share
|
||||
id: f63c34fe-a435-11eb-935a-acde48001122
|
||||
version: 2
|
||||
date: '2023-04-14'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,13 +33,14 @@ references:
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Active Directory Lateral Movement
|
||||
- Prestige Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
- Industroyer2
|
||||
- IcedID
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Trickbot
|
||||
- Prestige Ransomware
|
||||
- Data Destruction
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Executables Or Script Creation In Suspicious Path
|
||||
id: a7e3f0f0-ae42-11eb-b245-acde48001122
|
||||
version: 1
|
||||
date: '2023-04-25'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -38,26 +38,27 @@ references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Azorult
|
||||
- AsyncRAT
|
||||
- WhisperGate
|
||||
- XMRig
|
||||
- Swift Slicer
|
||||
- DarkCrystal RAT
|
||||
- Double Zero Destructor
|
||||
- Trickbot
|
||||
- Data Destruction
|
||||
- LockBit Ransomware
|
||||
- Industroyer2
|
||||
- Remcos
|
||||
- RedLine Stealer
|
||||
- WhisperGate
|
||||
- IcedID
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- AgentTesla
|
||||
- Brute Ratel C4
|
||||
- Azorult
|
||||
- DarkCrystal RAT
|
||||
- Graceful Wipe Out Attack
|
||||
- IcedID
|
||||
- Swift Slicer
|
||||
- Qakbot
|
||||
- Chaos Ransomware
|
||||
- RedLine Stealer
|
||||
- Brute Ratel C4
|
||||
- AsyncRAT
|
||||
- LockBit Ransomware
|
||||
- AgentTesla
|
||||
- Double Zero Destructor
|
||||
- Volt Typhoon
|
||||
- Chaos Ransomware
|
||||
- Trickbot
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 40
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: GPUpdate with no Command Line Arguments with Network
|
||||
id: 2c853856-a140-11eb-a5b5-acde48001122
|
||||
version: 2
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -34,6 +34,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Impacket Lateral Movement Commandline Parameters
|
||||
id: 8ce07472-496f-11ec-ab3b-3e22fbd008af
|
||||
version: 3
|
||||
date: '2023-04-14'
|
||||
date: '2023-06-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,13 +39,14 @@ references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Active Directory Lateral Movement
|
||||
- Prestige Ransomware
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
- Graceful Wipe Out Attack
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 90
|
||||
|
||||
@@ -1,20 +1,36 @@
|
||||
name: Impacket Lateral Movement smbexec CommandLine Parameters
|
||||
id: bb3c1bac-6bdf-4aa0-8dc9-068b8b712a76
|
||||
version: 1
|
||||
date: '2023-04-25'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
- Windows Security 4688
|
||||
description: This analytic focuses on identifying suspicious command-line parameters commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python classes designed for working with Microsoft network protocols, and it includes several scripts like wmiexec.py, smbexec.py, dcomexec.py, and atexec.py that enable command execution on remote endpoints. These scripts typically utilize administrative shares and hardcoded parameters, which can serve as signatures to detect their usage. Both Red Teams and adversaries may employ Impacket tools for lateral movement and remote code execution purposes. By monitoring for these specific command-line indicators, the analytic aims to detect potentially malicious activities related to Impacket tool usage.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process,"(?i)echo\s+cd") AND match(process, "(?i)\\__output") AND match(process, "(?i)C:\\\\Windows\\\\[a-zA-Z]{1,8}\\.bat") AND match(process, "\\\\127\.0\.0\.1\\.*")
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `impacket_lateral_movement_smbexec_commandline_parameters_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
description: This analytic focuses on identifying suspicious command-line parameters
|
||||
commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python
|
||||
classes designed for working with Microsoft network protocols, and it includes several
|
||||
scripts like wmiexec.py, smbexec.py, dcomexec.py, and atexec.py that enable command
|
||||
execution on remote endpoints. These scripts typically utilize administrative shares
|
||||
and hardcoded parameters, which can serve as signatures to detect their usage. Both
|
||||
Red Teams and adversaries may employ Impacket tools for lateral movement and remote
|
||||
code execution purposes. By monitoring for these specific command-line indicators,
|
||||
the analytic aims to detect potentially malicious activities related to Impacket
|
||||
tool usage.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process,"(?i)echo\s+cd")
|
||||
AND match(process, "(?i)\\__output") AND match(process, "(?i)C:\\\\Windows\\\\[a-zA-Z]{1,8}\\.bat") AND
|
||||
match(process, "\\\\127\.0\.0\.1\\.*") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `impacket_lateral_movement_smbexec_commandline_parameters_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Although uncommon, Administrators may leverage Impackets tools
|
||||
to start a process on remote systems for system administration or automation use
|
||||
cases.
|
||||
@@ -30,18 +46,20 @@ references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Active Directory Lateral Movement
|
||||
- Prestige Ransomware
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
- Graceful Wipe Out Attack
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
impact: 90
|
||||
message: Suspicious command-line parameters on $dest$ may represent lateral movement using smbexec.
|
||||
message: Suspicious command-line parameters on $dest$ may represent lateral movement
|
||||
using smbexec.
|
||||
mitre_attack_id:
|
||||
- T1021
|
||||
- T1021.002
|
||||
@@ -59,11 +77,11 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
@@ -72,4 +90,4 @@ tests:
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/smbexec_windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
sourcetype: xmlwineventlog
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Impacket Lateral Movement WMIExec Commandline Parameters
|
||||
id: d6e464e4-5c6a-474e-82d2-aed616a3a492
|
||||
version: 1
|
||||
date: '2023-04-21'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -16,12 +16,18 @@ description: This analytic looks for the presence of suspicious commandline para
|
||||
scripts leverage administrative shares and hardcoded parameters that can be used
|
||||
as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets
|
||||
tools for lateral movement and remote code execution.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process, "\\\\127\.0\.0\.1\\.*") AND match(process, "__\\d{1,10}\\.\\d{1,10}")
|
||||
| `security_content_ctime(firstTime)`
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| where match(process, "(?i)cmd\.exe\s+\/Q\s+\/c") AND match(process, "\\\\127\.0\.0\.1\\.*")
|
||||
AND match(process, "__\\d{1,10}\\.\\d{1,10}") | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`| `impacket_lateral_movement_wmiexec_commandline_parameters_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
|
||||
endpoint product.
|
||||
known_false_positives: Although uncommon, Administrators may leverage Impackets tools
|
||||
to start a process on remote systems for system administration or automation use
|
||||
cases.
|
||||
@@ -37,18 +43,20 @@ references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Active Directory Lateral Movement
|
||||
- Prestige Ransomware
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
- Graceful Wipe Out Attack
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
impact: 90
|
||||
message: Suspicious command-line parameters on $dest$ may represent lateral movement using wmiexec.
|
||||
message: Suspicious command-line parameters on $dest$ may represent lateral movement
|
||||
using wmiexec.
|
||||
mitre_attack_id:
|
||||
- T1021
|
||||
- T1021.002
|
||||
@@ -66,11 +74,11 @@ tags:
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- Processes.process_name
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name
|
||||
- Processes.process
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_id
|
||||
risk_score: 63
|
||||
security_domain: endpoint
|
||||
@@ -79,4 +87,4 @@ tests:
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021.002/atomic_red_team/wmiexec_windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
sourcetype: xmlwineventlog
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Net Localgroup Discovery
|
||||
id: 54f5201e-155b-11ec-a6e2-acde48001122
|
||||
version: 1
|
||||
date: '2021-09-14'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -30,13 +30,14 @@ references:
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Discovery
|
||||
- Windows Discovery Techniques
|
||||
- Azorult
|
||||
- Windows Post-Exploitation
|
||||
- Prestige Ransomware
|
||||
- Volt Typhoon
|
||||
- Graceful Wipe Out Attack
|
||||
- IcedID
|
||||
- Windows Discovery Techniques
|
||||
- Windows Post-Exploitation
|
||||
- Azorult
|
||||
- Active Directory Discovery
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 30
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Remote WMI Command Attempt
|
||||
id: 272df6de-61f1-4784-877c-1fbc3e2d0838
|
||||
version: 4
|
||||
date: '2018-12-03'
|
||||
date: '2023-06-13'
|
||||
author: Rico Valdez, Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,10 +31,11 @@ references:
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Volt Typhoon
|
||||
- Graceful Wipe Out Attack
|
||||
- IcedID
|
||||
- Suspicious WMI Use
|
||||
- Living Off The Land
|
||||
- Volt Typhoon
|
||||
- IcedID
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Rundll32 with no Command Line Arguments with Network
|
||||
id: 35307032-a12d-11eb-835f-acde48001122
|
||||
version: 4
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Steven Dick, Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,9 +40,10 @@ references:
|
||||
- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Rundll32 Activity
|
||||
- Cobalt Strike
|
||||
- PrintNightmare CVE-2021-34527
|
||||
- Suspicious Rundll32 Activity
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: SAM Database File Access Attempt
|
||||
id: 57551656-ebdb-11eb-afdf-acde48001122
|
||||
version: 1
|
||||
date: '2021-07-23'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: SearchProtocolHost with no Command Line with Network
|
||||
id: b690df8c-a145-11eb-a38b-acde48001122
|
||||
version: 3
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,6 +33,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: SecretDumps Offline NTDS Dumping Tool
|
||||
id: 5672819c-be09-11eb-bbfb-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-26'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,6 +29,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Services Escalate Exe
|
||||
id: c448488c-b7ec-11eb-8253-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-18'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,6 +36,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 95
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious DLLHost no Command Line Arguments
|
||||
id: ff61e98c-0337-4593-a78f-72a676c56f26
|
||||
version: 4
|
||||
date: '2023-03-08'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious GPUpdate no Command Line Arguments
|
||||
id: f308490a-473a-40ef-ae64-dd7a6eba284a
|
||||
version: 3
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious microsoft workflow compiler rename
|
||||
id: f0db4464-55d9-11eb-ae93-0242ac130002
|
||||
version: 4
|
||||
date: '2022-04-07'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -32,10 +32,11 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md#atomic-test-6---microsoftworkflowcompilerexe-payload-execution
|
||||
tags:
|
||||
analytic_story:
|
||||
- Trusted Developer Utilities Proxy Execution
|
||||
- Cobalt Strike
|
||||
- Masquerading - Rename System Utilities
|
||||
- Trusted Developer Utilities Proxy Execution
|
||||
- Graceful Wipe Out Attack
|
||||
- Living Off The Land
|
||||
- Cobalt Strike
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious msbuild path
|
||||
id: f5198224-551c-11eb-ae93-0242ac130002
|
||||
version: 3
|
||||
date: '2022-03-08'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,10 +32,11 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Masquerading - Rename System Utilities
|
||||
- Graceful Wipe Out Attack
|
||||
- Living Off The Land
|
||||
- Trusted Developer Utilities Proxy Execution MSBuild
|
||||
- Cobalt Strike
|
||||
- Masquerading - Rename System Utilities
|
||||
- Living Off The Land
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious MSBuild Rename
|
||||
id: 4006adac-5937-11eb-ae93-0242ac130002
|
||||
version: 3
|
||||
date: '2022-04-07'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -30,10 +30,11 @@ references:
|
||||
- https://github.com/infosecn1nja/MaliciousMacroMSBuild/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Masquerading - Rename System Utilities
|
||||
- Graceful Wipe Out Attack
|
||||
- Living Off The Land
|
||||
- Trusted Developer Utilities Proxy Execution MSBuild
|
||||
- Cobalt Strike
|
||||
- Masquerading - Rename System Utilities
|
||||
- Living Off The Land
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Process File Path
|
||||
id: 9be25988-ad82-11eb-a14f-acde48001122
|
||||
version: 1
|
||||
date: '2023-04-25'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,27 +36,28 @@ references:
|
||||
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Azorult
|
||||
- AsyncRAT
|
||||
- WhisperGate
|
||||
- XMRig
|
||||
- Swift Slicer
|
||||
- DarkCrystal RAT
|
||||
- Double Zero Destructor
|
||||
- Trickbot
|
||||
- Data Destruction
|
||||
- LockBit Ransomware
|
||||
- Prestige Ransomware
|
||||
- Industroyer2
|
||||
- Remcos
|
||||
- RedLine Stealer
|
||||
- WhisperGate
|
||||
- IcedID
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- AgentTesla
|
||||
- Brute Ratel C4
|
||||
- Azorult
|
||||
- DarkCrystal RAT
|
||||
- Graceful Wipe Out Attack
|
||||
- IcedID
|
||||
- Swift Slicer
|
||||
- Qakbot
|
||||
- Chaos Ransomware
|
||||
- RedLine Stealer
|
||||
- Brute Ratel C4
|
||||
- Prestige Ransomware
|
||||
- AsyncRAT
|
||||
- LockBit Ransomware
|
||||
- AgentTesla
|
||||
- Double Zero Destructor
|
||||
- Volt Typhoon
|
||||
- Chaos Ransomware
|
||||
- Trickbot
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Rundll32 no Command Line Arguments
|
||||
id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4
|
||||
version: 3
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,9 +32,10 @@ references:
|
||||
- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Rundll32 Activity
|
||||
- Cobalt Strike
|
||||
- PrintNightmare CVE-2021-34527
|
||||
- Suspicious Rundll32 Activity
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Rundll32 StartW
|
||||
id: 9319dda5-73f2-4d43-a85a-67ce961bddb7
|
||||
version: 3
|
||||
date: '2021-02-04'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,8 +37,9 @@ references:
|
||||
- https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Rundll32 Activity
|
||||
- Cobalt Strike
|
||||
- Suspicious Rundll32 Activity
|
||||
- Graceful Wipe Out Attack
|
||||
- Trickbot
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious SearchProtocolHost no Command Line Arguments
|
||||
id: f52d2db8-31f9-4aa7-a176-25779effe55c
|
||||
version: 3
|
||||
date: '2022-03-15'
|
||||
date: '2023-06-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Windows AdFind Exe
|
||||
id: bd3b0187-189b-46c0-be45-f52da2bae67f
|
||||
version: 3
|
||||
date: '2023-05-15'
|
||||
date: '2023-06-13'
|
||||
author: Jose Hernandez, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: 'This search looks for the execution of `adfind.exe` with command-line
|
||||
arguments that it uses by default specifically the filter or search functions.
|
||||
It also considers the arguments necessary like objectcategory, see readme for more
|
||||
details: https://www.joeware.net/freetools/tools/adfind/usage.htm. AdFind.exe is a powerful tool that is commonly used for querying and retrieving information from Active Directory (AD). While it is primarily designed for AD administration and management, it has been seen used before by Wizard Spider, FIN6 and actors whom also launched SUNBURST.'
|
||||
arguments that it uses by default specifically the filter or search functions. It
|
||||
also considers the arguments necessary like objectcategory, see readme for more
|
||||
details: https://www.joeware.net/freetools/tools/adfind/usage.htm. AdFind.exe is
|
||||
a powerful tool that is commonly used for querying and retrieving information from
|
||||
Active Directory (AD). While it is primarily designed for AD administration and
|
||||
management, it has been seen used before by Wizard Spider, FIN6 and actors whom
|
||||
also launched SUNBURST.'
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
@@ -21,7 +25,9 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, and command-line executions from your endpoints. If
|
||||
you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
||||
known_false_positives: ADfind is a command-line tool for AD administration and management that is seen to be leveraged by various adversaries. Filter out legitimate administrator usage using the filter macro.
|
||||
known_false_positives: ADfind is a command-line tool for AD administration and management
|
||||
that is seen to be leveraged by various adversaries. Filter out legitimate administrator
|
||||
usage using the filter macro.
|
||||
references:
|
||||
- https://www.volexity.com/blog/2020/12/14/dark-halo-leverages-solarwinds-compromise-to-breach-organizations/
|
||||
- https://www.mandiant.com/resources/a-nasty-trick-from-credential-theft-malware-to-business-disruption
|
||||
@@ -29,9 +35,10 @@ references:
|
||||
- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/
|
||||
tags:
|
||||
analytic_story:
|
||||
- NOBELIUM Group
|
||||
- Domain Trust Discovery
|
||||
- IcedID
|
||||
- NOBELIUM Group
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Process Injection Remote Thread
|
||||
id: 8a618ade-ca8f-4d04-b972-2d526ba59924
|
||||
version: 1
|
||||
date: '2022-11-10'
|
||||
date: '2023-06-15'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -16,7 +16,7 @@ data_source:
|
||||
- Sysmon Event ID 8
|
||||
search: '`sysmon` EventCode=8 TargetImage IN ("*\\Taskmgr.exe", "*\\calc.exe", "*\\notepad.exe",
|
||||
"*\\rdpclip.exe", "*\\explorer.exe", "*\\wermgr.exe", "*\\ping.exe", "*\\OneDriveSetup.exe",
|
||||
"*\\dxdiag.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\xwizard.exe") | stats count
|
||||
"*\\dxdiag.exe", "*\\mobsync.exe", "*\\msra.exe", "*\\xwizard.exe","*\\cmd.exe", "*\\powershell.exe") | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by TargetImage TargetProcessId SourceProcessId EventCode
|
||||
StartAddress SourceImage Computer | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `windows_process_injection_remote_thread_filter`'
|
||||
@@ -27,9 +27,11 @@ how_to_implement: To successfully implement this search, you must be ingesting d
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg
|
||||
- https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Qakbot
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: 80
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Raw Access To Disk Volume Partition
|
||||
id: a85aa37e-9647-11ec-90c5-acde48001122
|
||||
version: 1
|
||||
date: '2023-04-14'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -28,9 +28,10 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- CISA AA22-264A
|
||||
- Graceful Wipe Out Attack
|
||||
- Data Destruction
|
||||
- Caddy Wiper
|
||||
- Hermetic Wiper
|
||||
- Caddy Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Raw Access To Master Boot Record Drive
|
||||
id: 7b83f666-900c-11ec-a2d9-acde48001122
|
||||
version: 1
|
||||
date: '2023-04-14'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,11 +29,12 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Caddy Wiper
|
||||
- CISA AA22-264A
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Graceful Wipe Out Attack
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Caddy Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Service Stop By Deletion
|
||||
id: 196ff536-58d9-4d1b-9686-b176b04e430b
|
||||
version: 1
|
||||
date: '2022-06-21'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Azorult
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Service Stop Via Net and SC Application
|
||||
id: 827af04b-0d08-479b-9b84-b7d4644e4b80
|
||||
version: 1
|
||||
date: '2022-11-30'
|
||||
date: '2023-06-13'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Prestige Ransomware
|
||||
- Graceful Wipe Out Attack
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
name: Graceful Wipe Out Attack
|
||||
id: 83b15b3c-6bda-45aa-a3b6-b05c52443f44
|
||||
version: 1
|
||||
date: '2023-06-15'
|
||||
author: Teoderick Contreras, Splunk
|
||||
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities
|
||||
that might relate to the destructive attack or campaign found by "THE DFIR Report" that uses Truebot, FlawedGrace and MBR killer malware.
|
||||
This analytic story looks for suspicious dropped files, cobalt strike execution, im-packet execution, registry modification, scripts,
|
||||
persistence, lateral movement, impact, exfiltration and recon.
|
||||
narrative: Graceful Wipe Out Attack is a destructive malware campaign found by "The DFIR Report" targeting
|
||||
multiple organizations to collect, exfiltrate and wipe the data of targeted networks.
|
||||
This malicious payload corrupts or wipes Master Boot Records by using an NSIS script after the exfiltration of sensitive information from the targeted host or system.
|
||||
references:
|
||||
- https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/
|
||||
tags:
|
||||
analytic_story: Graceful Wipe Out Attack
|
||||
category:
|
||||
- Data Destruction
|
||||
- Malware
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user