Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-05-02 12:49:15 -07:00
committed by GitHub
12 changed files with 746 additions and 1 deletions
@@ -0,0 +1,68 @@
name: Windows Modify Registry Auto Minor Updates
id: be498b9f-d804-4bbf-9fc0-d5448466b313
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that will "Treat minor updates like other updates".
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\AU\\AutoInstallMinorUpdates"
AND Registry.registry_value_data="0x00000000"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_auto_minor_updates_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 30
impact: 30
message: A registry modification in Windows auto update configuration on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 9
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,68 @@
name: Windows Modify Registry Auto Update Notif
id: 4d1409df-40c7-4b11-aec4-bd0e709dfc12
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update notification.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that will switch the automatic windows update to "Notify before download".
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\AU\\AUOptions"
AND Registry.registry_value_data="0x00000002"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_auto_update_notif_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 50
impact: 50
message: A registry modification in Windows auto update notification on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,66 @@
name: Windows Modify Registry Disable WinDefender Notifications
id: 8e207707-ad40-4eb3-b865-3a52aec91f26
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: TTP
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification to disable Windows Defender notification.
This technique was being abused by several adversaries, malware authors and also red-teamers to evade detection on the targeted machine.
RedLine Stealer is one of the malware we've seen that uses this technique to bypass Windows defender detection.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows Defender Security Center\\Notifications\\DisableNotifications"
AND Registry.registry_value_data="0x00000001"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_disable_windefender_notifications_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 70
impact: 70
message: A registry modification to disable Windows Defender notification on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,70 @@
name: Windows Modify Registry Do Not Connect To Win Update
id: e09c598e-8dd0-4e73-b740-4b96b689199e
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that will disable Windos update functionality, and may cause connection to public services such as the Windows Store to stop working.
This policy applies only when this PC is configured to connect to an intranet update service using the "Specify intranet Microsoft update service location" policy.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\DoNotConnectToWindowsUpdateInternetLocations"
AND Registry.registry_value_data="0x00000001"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_do_not_connect_to_win_update_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
- https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsUpdate::DoNotConnectToWindowsUpdateInternetLocations
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 50
impact: 50
message: a registry modification in Windows auto update configuration in $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,68 @@
name: Windows Modify Registry No Auto Reboot With Logon User
id: 6a12fa9f-580d-4627-8c7f-313e359bdc6a
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that will allow "Logged-on user gets to choose whether or not to restart his or her compute".
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\AU\\NoAutoRebootWithLoggedOnUsers"
AND Registry.registry_value_data="0x00000001"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_no_auto_reboot_with_logon_user_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 30
impact: 30
message: A registry modification in Windows auto update configuration on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 9
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,68 @@
name: Windows Modify Registry No Auto Update
id: fbd4f333-17bb-4eab-89cb-860fa2e0600e
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that will "Disable Automatic Updates".
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\AU\\NoAutoUpdate"
AND Registry.registry_value_data="0x00000001"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_no_auto_update_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 70
impact: 70
message: A registry modification in Windows auto update configuration on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,66 @@
name: Windows Modify Registry Tamper Protection
id: 12094335-88fc-4c3a-b55f-e62dd8c93c23
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: TTP
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification to tamper Windows Defender protection.
This technique was being abused by several adversaries, malware authors and also red-teamers to evade detection on the targeted machine.
RedLine Stealer is one of the malware we've seen that uses this technique to bypass Windows defender detection.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Microsoft\\Windows Defender\\Features\\TamperProtection"
AND Registry.registry_value_data="0x00000000"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_tamper_protection_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Administrators may enable or disable this feature that may
cause some false positive.
references:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 70
impact: 70
message: A registry modification to tamper Windows Defender protection on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,67 @@
name: Windows Modify Registry UpdateServiceUrlAlternate
id: ca4e94fb-7969-4d63-8630-3625809a1f70
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that specifies an intranet server to host updates from Microsoft Update.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\UpdateServiceUrlAlternate"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_updateserviceurlalternate_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 50
impact: 50
message: A registry modification in Windows auto update configuration on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,68 @@
name: Windows Modify Registry USeWuServer
id: c427bafb-0b2c-4b18-ad85-c03c6fed9e75
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification that will use "The WUServer value unless this key is set".
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\AU\\UseWUServer"
AND Registry.registry_value_data="0x00000001"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_usewuserver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 50
impact: 50
message: a registry modification in Windows auto update configuration in $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,68 @@
name: Windows Modify Registry WuServer
id: a02ad386-e26d-44ce-aa97-6a46cee31439
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification related to the WSUS server used by Automatic Updates and (by default) API callers.
This policy is paired with WUStatusServer; both must be set to the same value in order for them to be valid.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\WUServer"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_wuserver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: Administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 50
impact: 50
message: A registry modification in Windows auto update configuration on $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,68 @@
name: Windows Modify Registry wuStatusServer
id: 073e69d0-68b2-4142-aa90-a7ee6f590676
version: 1
date: '2023-04-21'
author: Teoderick Contreras, Splunk
status: production
type: Hunting
data_source:
- Sysmon EventID 12
- Sysmon EventID 13
- Sysmon EventID 14
description: The following analytic identifies a suspicious registry modification of Windows auto update configuration.
This technique was being abused by several adversaries, malware authors and also red-teamers to bypass detection or
to be able to compromise the target host with zero day exploit or as an additional defense evasion technique.
RedLine Stealer is one of the malware we've seen that uses this technique to evade detection and add more payload on the target host.
This detection looks for registry modification related to the server to which reporting information will be sent for client computers
that use the WSUS server configured by the WUServer key. This policy is paired with WUServer; both must be set to the same value in order for them to be valid.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path="*\\SOFTWARE\\Policies\\Microsoft\\Windows\\WindowsUpdate\\WUStatusServer"
by Registry.dest Registry.user Registry.registry_path Registry.registry_value_data Registry.registry_key_name
| `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)`
| `windows_modify_registry_wustatusserver_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: administrators may enable or disable this feature that may
cause some false positive.
references:
- https://learn.microsoft.com/de-de/security-updates/windowsupdateservices/18127499
tags:
analytic_story:
- RedLine Stealer
asset_type: Endpoint
confidence: 50
impact: 50
message: a registry modification in Windows auto update configuration in $dest$
mitre_attack_id:
- T1112
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.user
- Registry.dest
- Registry.registry_value_name
- Registry.action
- Registry.registry_value_data
risk_score: 25
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/redline/modify_registry/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
+1 -1
View File
@@ -4,7 +4,7 @@ GitPython==3.1.31
Jinja2==3.1.2
jsonschema==4.17.3
mock==4.0.3
psutil==5.9.4
psutil==5.9.5
pycvesearch==1.2
pydantic==1.10.7
pysigma==0.9.8