From ee4d6c3b3c8df30a2bc450c19027abc59ec20ea6 Mon Sep 17 00:00:00 2001 From: root Date: Wed, 8 Sep 2021 02:26:36 +0000 Subject: [PATCH] Added detection testing service results inGet-ForestTrust with PowerShell --- .../get_foresttrust_with_powershell.yml | 52 +++++++++++-------- 1 file changed, 30 insertions(+), 22 deletions(-) diff --git a/detections/endpoint/get_foresttrust_with_powershell.yml b/detections/endpoint/get_foresttrust_with_powershell.yml index 6a1db314d3..1be7206560 100644 --- a/detections/endpoint/get_foresttrust_with_powershell.yml +++ b/detections/endpoint/get_foresttrust_with_powershell.yml @@ -6,25 +6,32 @@ author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: 'This analytic identifies Get-ForestTrust from PowerSploit in order to gather domain trust information. - Typically, this is utilized within a script being executed and used to enumerate the domain trust information. This grants the adversary an understanding of how large or small the domain is. - During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity.' +description: This analytic identifies Get-ForestTrust from PowerSploit in order to + gather domain trust information. Typically, this is utilized within a script being + executed and used to enumerate the domain trust information. This grants the adversary + an understanding of how large or small the domain is. During triage, review parallel + processes using an EDR product or 4688 events. It will be important to understand + the timeline of events around this activity. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe - Processes.process=*get-foresttrust* by Processes.dest Processes.user Processes.parent_process_name Processes.process_name - Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `get_foresttrust_with_powershell_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: Limited false positives as this requires an active Administrator or adversary to bring in, import, and execute. + as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe + OR Processes.process_name=cmd.exe Processes.process=*get-foresttrust* by Processes.dest + Processes.user Processes.parent_process_name Processes.process_name Processes.process + Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `get_foresttrust_with_powershell_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Limited false positives as this requires an active Administrator + or adversary to bring in, import, and execute. references: - - https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/ +- https://powersploit.readthedocs.io/en/latest/Recon/Get-ForestTrust/ tags: analytic_story: - Active Directory Discovery - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/discovery/windows-sysmon.log kill_chain_phases: - Reconnaissance mitre_attack_id: @@ -37,24 +44,24 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id security_domain: endpoint - impact: 30 + impact: 30 confidence: 40 - # (impact * confidence)/100 risk_score: 12 context: - Source:Endpoint - Stage:Defense Evasion - message: Suspicious PowerShell Get-ForestTrust was identified on endpoint $dest$ by user $user$. + message: Suspicious PowerShell Get-ForestTrust was identified on endpoint $dest$ + by user $user$. observable: - name: user type: User @@ -63,4 +70,5 @@ tags: - name: dest type: Hostname role: - - Victim \ No newline at end of file + - Victim + automated_detection_testing: passed