Merge pull request #1171 from splunk/Tr-408_bug_fix

bug fix detection First Time Seen Running Windows Service
This commit is contained in:
P4T12ICK
2021-02-03 17:35:22 +01:00
committed by GitHub
3 changed files with 2 additions and 20 deletions
@@ -20,7 +20,7 @@ search: '`wineventlog_system` EventCode=7036 |
rex field=Message "The (?<service>[-\(\)\s\w]+) service entered the (?<state>\w+) state" |
where state="running" |
lookup previously_seen_running_windows_services service as service OUTPUT firstTimeSeen |
where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), "`previously_seen_windows_service_window`") |
where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), `previously_seen_windows_services_window`) |
table _time dest service | `first_time_seen_running_windows_service_filter`'
known_false_positives: A previously unseen service is not necessarily malicious. Verify
that the service is legitimate and that was installed by a legitimate process.
@@ -1,3 +1,3 @@
description: Use this macro to determine how far back you should be checking for new Windows services
definition: '"-70m@m"'
name: previously_seen_windows_service_window
name: previously_seen_windows_services_window
@@ -1,18 +0,0 @@
name: First Time Seen Running Windows Service Unit Test
tests:
- name: First Time Seen Running Windows Service
file: endpoint/first_time_seen_running_windows_service.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
baselines:
- name: Previously Seen Running Windows Services - Initial
file: baselines/previously_seen_running_windows_services.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: '-70m@m'
attack_data:
- file_name: windows-system.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/first_time_windows_service/windows-system.log
source: WinEventLog:System
sourcetype: WinEventLog