diff --git a/bin/generate.py b/bin/generate.py index 61ecf0980b..01ad77db51 100644 --- a/bin/generate.py +++ b/bin/generate.py @@ -709,7 +709,7 @@ def write_use_case_lib_conf(stories, detections, investigations, baselines, OUTP output_file.write("confidence = {0}\n".format(detection['confidence'])) output_file.write("explanation = {0}\n".format(detection['eli5'])) output_file.write("how_to_implement = {0}\n".format(detection['how_to_implement'])) - output_file.write("annotations = {0}\n".format(detection['mappings'])) + output_file.write("annotations = {0}\n".format(json.dumps(detection['mappings']))) output_file.write("known_false_positives = {0}\n".format(detection['known_false_positives'])) output_file.write("providing_technologies = {0}\n".format(json.dumps(detection['providing_technologies']))) output_file.write("\n") diff --git a/src/default/analytic_stories.conf b/src/default/analytic_stories.conf index 71f835cb9c..88976dd694 100644 --- a/src/default/analytic_stories.conf +++ b/src/default/analytic_stories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-04-22T22:51:31 UTC +# On Date: 2019-04-22T23:02:58 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/src/default/savedsearches.conf b/src/default/savedsearches.conf index a780cbb6f6..6b4ad8a1a7 100644 --- a/src/default/savedsearches.conf +++ b/src/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-04-22T22:51:31 UTC +# On Date: 2019-04-22T23:02:58 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -24,7 +24,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Suspicious Provisioning Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -77,7 +77,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Suspicious Provisioning Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -130,7 +130,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Suspicious Provisioning Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -183,7 +183,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Suspicious Provisioning Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -252,7 +252,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Cross Account Activity"] cron_schedule = 5 * * * * dispatch.earliest_time = -70m@m @@ -303,7 +303,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Network Access Control List Created with All Open Ports - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Network ACL Activity"] cron_schedule = 0 * * * * dispatch.earliest_time = -1d@d @@ -354,7 +354,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - AWS Network Access Control List Deleted - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Network ACL Activity"] cron_schedule = 0 * * * * dispatch.earliest_time = -1d@d @@ -405,7 +405,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Abnormally High AWS Instances Launched by User - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Cryptomining", "Suspicious AWS EC2 Activities"] cron_schedule = */10 * * * * dispatch.earliest_time = -30d@d @@ -456,7 +456,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Abnormally High AWS Instances Terminated by User - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["Suspicious AWS EC2 Activities"] cron_schedule = */10 * * * * dispatch.earliest_time = -30d@d @@ -508,7 +508,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Attempt To Add Certificate To Untrusted Store - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Disabling Security Tools"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -560,7 +560,7 @@ action.escu.confidence = High action.escu.full_search_name = ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Credential Dumping", "Malicious PowerShell"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -612,7 +612,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Attempt To Stop Security Service - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Disabling Security Tools"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -664,7 +664,7 @@ action.escu.confidence = High action.escu.full_search_name = ESCU - Attempted Credential Dump From Registry Via Reg.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Credential Dumping"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -716,7 +716,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Batch File Write to System32 - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -768,7 +768,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Child Processes of Spoolsv.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows Privilege Escalation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -820,7 +820,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Clients Connecting to Multiple DNS Servers - Rule action.escu.search_type = detection action.escu.fields_required = ["dest", "src"] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "DNS Hijacking", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -872,7 +872,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Common Ransomware Extensions - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Ransomware", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -924,7 +924,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Common Ransomware Notes - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Ransomware", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -976,7 +976,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Create local admin accounts using net.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A"] cron_schedule = 0 8 * * * dispatch.earliest_time = -1440m@m @@ -1028,7 +1028,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Create or delete hidden shares using net.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Hidden Cobra Malware"] cron_schedule = 5 * * * * dispatch.earliest_time = -70m@m @@ -1080,7 +1080,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - DNS Query Length With High Standard Deviation - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "Hidden Cobra Malware", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1132,7 +1132,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule action.escu.search_type = detection action.escu.fields_required = ["dest", "src"] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "DNS Hijacking", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1192,7 +1192,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - DNS record changed - Rule action.escu.search_type = detection action.escu.fields_required = ["src", "dest"] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["DNS Hijacking"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1244,7 +1244,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Deleting Shadow Copies - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "SamSam Ransomware", "Windows Log Manipulation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1295,7 +1295,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect API activity from users without MFA - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS User Monitoring"] cron_schedule = 0 8 * * * dispatch.earliest_time = -1d@d @@ -1346,7 +1346,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect AWS API Activities From Unapproved Accounts - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS User Monitoring"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1397,7 +1397,7 @@ action.escu.confidence = low action.escu.full_search_name = ESCU - Detect Activity Related to Pass the Hash Attacks - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Lateral Movement"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1449,7 +1449,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule action.escu.search_type = detection action.escu.fields_required = ["src"] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Common Phishing Frameworks"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1509,7 +1509,7 @@ action.escu.confidence = low action.escu.full_search_name = ESCU - Detect Excessive Account Lockouts From Endpoint - Rule action.escu.search_type = detection action.escu.fields_required = ["dest"] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Account Monitoring and Controls"] cron_schedule = 0 * * * * dispatch.earliest_time = -4h@h @@ -1561,7 +1561,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Excessive User Account Lockouts - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Account Monitoring and Controls"] cron_schedule = 0 * * * * dispatch.earliest_time = -4h@h @@ -1613,7 +1613,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Large Outbound ICMP Packets - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream', u'Palo Alto Firewall'] +action.escu.providing_technologies = ["Bro", "Splunk Stream", "Palo Alto Firewall"] action.escu.analytic_story = ["Command and Control"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1665,7 +1665,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Long DNS TXT Record Response - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1716,7 +1716,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Mimikatz Via PowerShell And EventCode 4663 - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Credential Dumping"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1767,7 +1767,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Credential Dumping"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -1818,7 +1818,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect New Local Admin account - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["DHS Report TA18-074A"] cron_schedule = 0 9 * * * dispatch.earliest_time = -1440m@m @@ -1870,7 +1870,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect New Login Attempts to Routers - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Active Directory', u'Palo Alto Firewall'] +action.escu.providing_technologies = ["Active Directory", "Palo Alto Firewall"] action.escu.analytic_story = ["Router & Infrastructure Security"] cron_schedule = 0 0 * * * dispatch.earliest_time = -30d@d @@ -1921,7 +1921,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect New Open S3 buckets - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["Suspicious AWS S3 Activities"] cron_schedule = 5 * * * * dispatch.earliest_time = -70m@m @@ -1973,7 +1973,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Detect Oulook.exe writing a .zip file - Rule action.escu.search_type = detection action.escu.fields_required = ["dest"] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Phishing Payloads"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2025,7 +2025,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Outbound SMB Traffic - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Bro", "Splunk Stream"] action.escu.analytic_story = ["DHS Report TA18-074A", "Hidden Cobra Malware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2077,7 +2077,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Path Interception By Creation Of program.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows Persistence Techniques"] cron_schedule = 30 * * * * dispatch.earliest_time = -70m@m @@ -2129,7 +2129,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Prohibited Applications Spawning cmd.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious Command-Line Executions", "Suspicious MSHTA Activity"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2181,7 +2181,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect PsExec With accepteula Flag - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Sysmon'] +action.escu.providing_technologies = ["Sysmon"] action.escu.analytic_story = ["DHS Report TA18-074A", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2233,7 +2233,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Rare Executables - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Emotet Malware (TA18-201A)", "Unusual Processes"] cron_schedule = 10 * * * * dispatch.earliest_time = -70m@m @@ -2284,7 +2284,7 @@ action.escu.confidence = low action.escu.full_search_name = ESCU - Detect S3 access from a new IP - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["Suspicious AWS S3 Activities"] cron_schedule = 5 * * * * dispatch.earliest_time = -70m@m @@ -2357,7 +2357,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Spike in AWS API Activity - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS User Monitoring"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2430,7 +2430,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Spike in Network ACL Activity - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Network ACL Activity"] cron_schedule = 10 * * * * dispatch.earliest_time = -70m@m @@ -2503,7 +2503,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Spike in S3 Bucket deletion - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["Suspicious AWS S3 Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2576,7 +2576,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Spike in Security Group Activity - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS User Monitoring"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2645,7 +2645,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Network ACL Activity", "Command and Control", "Suspicious AWS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2697,7 +2697,7 @@ action.escu.confidence = low action.escu.full_search_name = ESCU - Detect USB device insertion - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Data Protection"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2749,7 +2749,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Unauthorized Assets by MAC address - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Asset Tracking"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2801,7 +2801,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect Use of cmd.exe to Launch Script Interpreters - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Emotet Malware (TA18-201A)", "Suspicious Command-Line Executions"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2853,7 +2853,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Apache', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Apache", "Bro"] action.escu.analytic_story = ["JBoss Vulnerability", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2905,7 +2905,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect hosts connecting to dynamic domain providers - Rule action.escu.search_type = detection action.escu.fields_required = ["dest", "query"] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "DNS Hijacking", "Data Protection", "Dynamic DNS", "Prohibited Traffic Allowed or Protocol Mismatch", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -2957,7 +2957,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Detect malicious requests to exploit JBoss servers - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Apache', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Apache", "Bro"] action.escu.analytic_story = ["JBoss Vulnerability", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3009,7 +3009,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect mshta.exe running scripts in command-line arguments - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious MSHTA Activity"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3060,7 +3060,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect new API calls from user roles - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS User Monitoring"] cron_schedule = 30 * * * * dispatch.earliest_time = -70m@m @@ -3111,7 +3111,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detect new user AWS Console Login - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["Suspicious AWS Login Activities"] cron_schedule = 5 * * * * dispatch.earliest_time = -70m@m @@ -3163,7 +3163,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Detect processes used for System Network Configuration Discovery - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Unusual Processes"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3215,7 +3215,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Detect web traffic to dynamic domain providers - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro', u'Bluecoat', u'Palo Alto Firewall'] +action.escu.providing_technologies = ["Splunk Stream", "Bro", "Bluecoat", "Palo Alto Firewall"] action.escu.analytic_story = ["Dynamic DNS"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3267,7 +3267,7 @@ action.escu.confidence = low action.escu.full_search_name = ESCU - Detection of DNS Tunnels - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "Data Protection", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3319,7 +3319,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Detection of tools built by NirSoft - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Emotet Malware (TA18-201A)"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3371,7 +3371,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Disabling Remote User Account Control - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious Windows Registry Activities", "Windows Defense Evasion Tactics"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3422,7 +3422,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - EC2 Instance Modified With Previously Unseen User - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["Unusual AWS EC2 Modifications"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3473,7 +3473,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - EC2 Instance Started In Previously Unseen Region - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Cryptomining", "Suspicious AWS EC2 Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3524,7 +3524,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - EC2 Instance Started With Previously Unseen AMI - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Cryptomining"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3575,7 +3575,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Cryptomining"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3626,7 +3626,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - EC2 Instance Started With Previously Unseen User - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'AWS'] +action.escu.providing_technologies = ["AWS"] action.escu.analytic_story = ["AWS Cryptomining", "Suspicious AWS EC2 Activities"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3678,7 +3678,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Email Attachments With Lots Of Spaces - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Exchange'] +action.escu.providing_technologies = ["Microsoft Exchange"] action.escu.analytic_story = ["Emotet Malware (TA18-201A)", "Suspicious Emails"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3730,7 +3730,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Email files written outside of the Outlook directory - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Collection and Staging"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3782,7 +3782,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Email servers sending high volume traffic to hosts - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Bro", "Splunk Stream"] action.escu.analytic_story = ["Collection and Staging"] cron_schedule = 0 0 * * * dispatch.earliest_time = -30d@d @@ -3834,7 +3834,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Excessive DNS Failures - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Command and Control", "Suspicious DNS Traffic"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3886,7 +3886,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Execution of File With Spaces Before Extension - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows File Extension and Association Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3938,7 +3938,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Execution of File with Multiple Extensions - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows File Extension and Association Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -3989,7 +3989,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Extended Period Without Successful Netbackup Backups - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Netbackup'] +action.escu.providing_technologies = ["Netbackup"] action.escu.analytic_story = ["Monitor Backup Solution"] cron_schedule = 0 0 1 * * dispatch.earliest_time = -7d@d @@ -4041,7 +4041,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - File with Samsam Extension - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4092,7 +4092,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - First Time Seen Running Windows Service - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Orangeworm Attack Group", "Windows Service Abuse"] cron_schedule = 30 * * * * dispatch.earliest_time = -70m@m @@ -4144,7 +4144,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - First time seen command line argument - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A", "Hidden Cobra Malware", "Orangeworm Attack Group", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Suspicious Command-Line Executions"] cron_schedule = 30 * * * * dispatch.earliest_time = -70m@m @@ -4196,7 +4196,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Hiding Files And Directories With Attrib.exe - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows Defense Evasion Tactics", "Windows Persistence Techniques"] cron_schedule = 30 * * * * dispatch.earliest_time = -70m@m @@ -4248,7 +4248,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Hosts receiving high volume of network traffic from email server - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Bro", "Splunk Stream"] action.escu.analytic_story = ["Collection and Staging"] cron_schedule = 0 0 * * * dispatch.earliest_time = -30d@d @@ -4300,7 +4300,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Identify New User Accounts - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Active Directory'] +action.escu.providing_technologies = ["Active Directory"] action.escu.analytic_story = ["Account Monitoring and Controls"] cron_schedule = 0 0 * * * dispatch.earliest_time = -24h@h @@ -4352,7 +4352,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Large Volume of DNS ANY Queries - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["DNS Amplification Attacks"] cron_schedule = */5 * * * * dispatch.earliest_time = -15m@m @@ -4404,7 +4404,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Malicious PowerShell", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4456,7 +4456,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Malicious PowerShell Process - Encoded Command - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Malicious PowerShell"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4508,7 +4508,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A"] cron_schedule = 50 * * * * dispatch.earliest_time = -70m@m @@ -4560,7 +4560,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Malicious PowerShell"] cron_schedule = 50 * * * * dispatch.earliest_time = -70m@m @@ -4612,7 +4612,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Malicious PowerShell"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4664,7 +4664,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Monitor DNS For Brand Abuse - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Brand Monitoring"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4716,7 +4716,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Monitor Email For Brand Abuse - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Exchange', u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Microsoft Exchange", "Bro", "Splunk Stream"] action.escu.analytic_story = ["Brand Monitoring"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4768,7 +4768,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Monitor Registry Keys for Print Monitors - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Suspicious Windows Registry Activities", "Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4820,7 +4820,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Monitor Web Traffic For Brand Abuse - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro', u'Bluecoat', u'Palo Alto Firewall'] +action.escu.providing_technologies = ["Splunk Stream", "Bro", "Bluecoat", "Palo Alto Firewall"] action.escu.analytic_story = ["Brand Monitoring"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4872,7 +4872,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - No Windows Updates in a time frame - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Monitor for Updates"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4924,7 +4924,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Open Redirect in Splunk Web - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Enterprise'] +action.escu.providing_technologies = ["Splunk Enterprise"] action.escu.analytic_story = ["Splunk Enterprise Vulnerability"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -4976,7 +4976,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Osquery pack - ColdRoot detection - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'OSquery'] +action.escu.providing_technologies = ["OSquery"] action.escu.analytic_story = ["ColdRoot MacOS RAT"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5028,7 +5028,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Overwriting Accessibility Binaries - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Windows Privilege Escalation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5080,7 +5080,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Process Execution via WMI - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious WMI Use"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5132,7 +5132,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Processes Tapping Keyboard Events - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'OSquery'] +action.escu.providing_technologies = ["OSquery"] action.escu.analytic_story = ["ColdRoot MacOS RAT"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5184,7 +5184,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Processes created by netsh - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Netsh Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5236,7 +5236,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Processes launching netsh - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A", "Disabling Security Tools", "Netsh Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5288,7 +5288,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Prohibited Network Traffic Allowed - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Palo Alto Firewall', u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Palo Alto Firewall", "Bro", "Splunk Stream"] action.escu.analytic_story = ["Command and Control", "Prohibited Traffic Allowed or Protocol Mismatch", "Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5340,7 +5340,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Prohibited Software On Endpoint - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Emotet Malware (TA18-201A)", "Monitor for Unauthorized Software", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5392,7 +5392,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Protocol or Port Mismatch - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Palo Alto Firewall', u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Palo Alto Firewall", "Bro", "Splunk Stream"] action.escu.analytic_story = ["Command and Control", "Prohibited Traffic Allowed or Protocol Mismatch"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5444,7 +5444,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Protocols passing authentication in cleartext - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["Use of Cleartext Protocols"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5496,7 +5496,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Reg.exe Manipulating Windows Services Registry Keys - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows Persistence Techniques", "Windows Service Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5548,7 +5548,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Reg.exe used to hide files/directories via registry keys - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious Windows Registry Activities", "Windows Defense Evasion Tactics", "Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5600,7 +5600,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Registry Keys Used For Persistence - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["DHS Report TA18-074A", "Emotet Malware (TA18-201A)", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Ransomware", "Suspicious MSHTA Activity", "Suspicious Windows Registry Activities", "Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5652,7 +5652,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Registry Keys Used For Privilege Escalation - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Suspicious Windows Registry Activities", "Windows Privilege Escalation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5704,7 +5704,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Registry Keys for Creating SHIM Databases - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Suspicious Windows Registry Activities", "Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5756,7 +5756,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Remote Desktop Network Bruteforce - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Bro", "Splunk Stream"] action.escu.analytic_story = ["SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5808,7 +5808,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Remote Desktop Network Traffic - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Bro", "Splunk Stream"] action.escu.analytic_story = ["Hidden Cobra Malware", "Lateral Movement", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5860,7 +5860,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Remote Desktop Process Running On System - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Hidden Cobra Malware", "Lateral Movement"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5912,7 +5912,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Remote Process Instantiation via WMI - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "Suspicious WMI Use"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -5964,7 +5964,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Remote Registry Key modifications - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Lateral Movement", "Suspicious Windows Registry Activities", "Windows Defense Evasion Tactics", "Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6016,7 +6016,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Remote WMI Command Attempt - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious WMI Use"] cron_schedule = 50 * * * * dispatch.earliest_time = -70m@m @@ -6068,7 +6068,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - RunDLL Loading DLL By Ordinal - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Unusual Processes"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6120,7 +6120,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - SMB Traffic Spike - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Bro", "Splunk Stream"] action.escu.analytic_story = ["DHS Report TA18-074A", "Emotet Malware (TA18-201A)", "Hidden Cobra Malware", "Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -7d@d @@ -6172,7 +6172,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - SQL Injection with Long URLs - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Bro"] action.escu.analytic_story = ["SQL Injection"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6224,7 +6224,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Samsam Test File Write - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6276,7 +6276,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Sc.exe Manipulating Windows Services - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A", "Disabling Security Tools", "Orangeworm Attack Group", "Windows Persistence Techniques", "Windows Service Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6328,7 +6328,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Scheduled Task Name Used by Dragonfly Threat Actors - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6380,7 +6380,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Scheduled tasks used in BadRabbit ransomware - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6432,7 +6432,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Schtasks scheduling job on remote system - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Lateral Movement"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6484,7 +6484,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Schtasks used for forcing a reboot - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -5h@h @@ -6536,7 +6536,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Script Execution via WMI - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious WMI Use"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6588,7 +6588,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Shim Database File Creation - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6640,7 +6640,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Shim Database Installation With Suspicious Parameters - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Windows Persistence Techniques"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6692,7 +6692,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Short Lived Windows Accounts - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Account Monitoring and Controls"] cron_schedule = 0 0,4,8,12,16,20 * * * dispatch.earliest_time = -245m@m @@ -6744,7 +6744,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Single Letter Process On Endpoint - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6796,7 +6796,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Spectre and Meltdown Vulnerable Systems - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Nessus', u'Qualys'] +action.escu.providing_technologies = ["Nessus", "Qualys"] action.escu.analytic_story = ["Spectre And Meltdown Vulnerabilities"] cron_schedule = 0 6 * * * dispatch.earliest_time = -25h@h @@ -6848,7 +6848,7 @@ action.escu.confidence = low action.escu.full_search_name = ESCU - Spike in File Writes - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "SamSam Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -7d@d @@ -6899,7 +6899,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Splunk Enterprise Information Disclosure - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Enterprise'] +action.escu.providing_technologies = ["Splunk Enterprise"] action.escu.analytic_story = ["Splunk Enterprise Vulnerability CVE-2018-11409"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -6951,7 +6951,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Suspicious Changes to File Associations - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Suspicious Windows Registry Activities", "Windows File Extension and Association Abuse"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7003,7 +7003,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Suspicious Email Attachment Extensions - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Exchange'] +action.escu.providing_technologies = ["Microsoft Exchange"] action.escu.analytic_story = ["Emotet Malware (TA18-201A)", "Suspicious Emails"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7055,7 +7055,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Suspicious File Write - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Hidden Cobra Malware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7106,7 +7106,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Suspicious Java Classes - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Bro', u'Bluecoat', u'Apache'] +action.escu.providing_technologies = ["Splunk Stream", "Bro", "Bluecoat", "Apache"] action.escu.analytic_story = ["Apache Struts Vulnerability"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7158,7 +7158,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Suspicious LNK file launching a process - Rule action.escu.search_type = detection action.escu.fields_required = ["dest"] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Phishing Payloads"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7210,7 +7210,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Suspicious Reg.exe Process - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["DHS Report TA18-074A", "Disabling Security Tools", "Windows Defense Evasion Tactics"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7262,7 +7262,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Suspicious wevtutil Usage - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "Windows Log Manipulation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7313,7 +7313,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Suspicious writes to System Volume Information - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Sysmon'] +action.escu.providing_technologies = ["Sysmon"] action.escu.analytic_story = ["Collection and Staging"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7365,7 +7365,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Suspicious writes to windows Recycle Bin - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Sysmon'] +action.escu.providing_technologies = ["Sysmon"] action.escu.analytic_story = ["Collection and Staging"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7417,7 +7417,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - System Processes Run From Unexpected Locations - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "Suspicious Command-Line Executions", "Unusual Processes"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7469,7 +7469,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - TOR Traffic - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Palo Alto Firewall', u'Bro', u'Splunk Stream'] +action.escu.providing_technologies = ["Palo Alto Firewall", "Bro", "Splunk Stream"] action.escu.analytic_story = ["Command and Control", "Prohibited Traffic Allowed or Protocol Mismatch", "Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7521,7 +7521,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - USN Journal Deletion - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Ransomware", "Windows Log Manipulation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7573,7 +7573,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Uncommon Processes On Endpoint - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Unusual Processes", "Windows Privilege Escalation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7624,7 +7624,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Unsuccessful Netbackup backups - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Netbackup'] +action.escu.providing_technologies = ["Netbackup"] action.escu.analytic_story = ["Monitor Backup Solution"] cron_schedule = 0 7 * * * dispatch.earliest_time = -24h@h @@ -7676,7 +7676,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Unusually Long Command Line - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "Ransomware", "Suspicious Command-Line Executions", "Unusual Processes"] cron_schedule = 0 * * * * dispatch.earliest_time = -1d@d @@ -7727,7 +7727,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Unusually Long Content-Type Length - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream'] +action.escu.providing_technologies = ["Splunk Stream"] action.escu.analytic_story = ["Apache Struts Vulnerability"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7778,7 +7778,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - WMI Permanent Event Subscription - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Suspicious WMI Use"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7829,7 +7829,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - WMI Permanent Event Subscription - Sysmon - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Suspicious WMI Use"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7880,7 +7880,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - WMI Temporary Event Subscription - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Suspicious WMI Use"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -7931,7 +7931,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Web Fraud - Account Harvesting - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Bro"] action.escu.analytic_story = ["Web Fraud Detection"] cron_schedule = 0 1 * * * dispatch.earliest_time = -1445m@m @@ -7982,7 +7982,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Web Fraud - Anomalous User Clickspeed - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Bro"] action.escu.analytic_story = ["Web Fraud Detection"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -8033,7 +8033,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Web Fraud - Password Sharing Across Accounts - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Bro'] +action.escu.providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Bro"] action.escu.analytic_story = ["Web Fraud Detection"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -8085,7 +8085,7 @@ action.escu.confidence = medium action.escu.full_search_name = ESCU - Web Servers Executing Suspicious Processes - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] action.escu.analytic_story = ["Apache Struts Vulnerability"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -8136,7 +8136,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Windows Event Log Cleared - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Microsoft Windows'] +action.escu.providing_technologies = ["Microsoft Windows"] action.escu.analytic_story = ["Ransomware", "Windows Log Manipulation"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m @@ -8188,7 +8188,7 @@ action.escu.confidence = high action.escu.full_search_name = ESCU - Windows hosts file modification - Rule action.escu.search_type = detection action.escu.fields_required = [] -action.escu.providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +action.escu.providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] action.escu.analytic_story = ["Host Redirection"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m diff --git a/src/default/use_case_library.conf b/src/default/use_case_library.conf index 06d27a2127..887850ac04 100644 --- a/src/default/use_case_library.conf +++ b/src/default/use_case_library.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-04-22T22:51:31 UTC +# On Date: 2019-04-22T23:02:58 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -1002,9 +1002,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns all events with event names that start with "Run" or "Create," and then does a GeoIP lookup on the IP address that initiated the action within the last hour. It appends the historical data to those results in the lookup file. Next, it recalculates the firstTime and lastTime field for each country, region, city, and IP address and outputs this data to the lookup file to update the local cache. It then calculates the firstTime and lastTime for each city. It returns only those events from cities that have first been seen in the past hour. This is combined with the main search to return the time, user, IP address, city, event name, and error code from the action. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.

This search will fire any time a new city is seen in the GeoIP database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your city, there should be few false positives. If you are located in countries where the free version of MaxMind GeoIP that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule] type = detection @@ -1012,9 +1012,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns all events with event names that start with "Run" or "Create," and then does a GeoIP lookup on the IP address that initiated the action within the last hour. It appends the historical data to those results in the lookup file. Next, it recalculates the firstTime and lastTime field for each country, region, city, and IP address and outputs this data to the lookup file to update the local cache. It then calculates the firstTime and lastTime for each country. It returns only those events from countries that have first been seen in the past hour. This is combined with the main search to return the time, user, IP address, city, event name, and error code from the action. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching over plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.

This search will fire any time a new country is seen in the GeoIP database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of MaxMind GeoIP that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule] type = detection @@ -1022,9 +1022,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns all events with event names that start with "Run" or "Create," and then does a GeoIP lookup on the IP address that initiated the action within the last hour. It appends the historical data to those results in the lookup file. Next, it recalculates the firstTime and lastTime field for each country, region, city, and IP address and outputs this data to the lookup file to update the local cache. It then calculates the firstTime and lastTime for each city. It returns only those events from IP addresses that have first been seen in the past hour. This is combined with the main search to return the time, user, IP address, city, event name, and error code from the action. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.

This search will fire any time a new IP address is seen in the GeoIP database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your country, there should be few false positives. If you are located in countries where the free version of MaxMind GeoIP that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule] type = detection @@ -1032,9 +1032,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns all events with event names that start with "Run" or "Create," and then does a GeoIP lookup on the IP address that initiated the action within the last hour. It appends the historical data to those results in the lookup file. Next, it recalculates the firstTime and lastTime field for each country, region, city, and IP address and outputs this data to the lookup file to update the local cache. It then calculates the firstTime and lastTime for each city. It returns only those events from regions that have first been seen in the past hour. This is combined with the main search to return the time, user, IP address, city, event name, and error code from the action. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen AWS Provisioning Activity Sources" support search once to create a history of previously seen locations that have provisioned AWS resources. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = This is a strictly behavioral search, so we define "false positive" slightly differently. Every time this fires, it will accurately reflect the first occurrence in the time period you're searching within, plus what is stored in the cache feature. But while there are really no "false positives" in a traditional sense, there is definitely lots of noise.

This search will fire any time a new region is seen in the GeoIP database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your region, there should be few false positives. If you are located in regions where the free version of MaxMind GeoIP that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule] type = detection @@ -1042,9 +1042,9 @@ asset_type = AWS Instance confidence = medium explanation = This search
  1. Retrieves the AssumeRole event
  2. Verifies that the log entry contains a value for the account ID of the requesting account
  3. Ensures that the requesting account ID does not match the account ID of the requested account
  4. Pulls in the previously seen requesting and requested account IDs
  5. Splits up and executes multiple search paths at the same.
  6. The first path determines the firstTime and lastTime entries for the cache file
  7. Outputs the data to the cache file.
  8. Creates a conditional statement that is always false (both because we don't want these values to exit the search pipeline and because we think we're clever).
The second pipeline adds the firstTime and lastTime entries to search results. Next, it filters out any account pairs that haven't been seen for the first time within the last hour. The isnotnull(_time) will remove the entries from the cache file.

The search finishes by gathering the data that it will display to the user. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Run the Previously Seen AWS Cross Account Activity support search only once to create the baseline of previously seen cross account activity. Thanks to Pablo Vega at Recurly for suggesting improvements to the search. -annotations = {u'mitre_attack': [u'Credential Access'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 16'], u'nist': [u'PR.AC', u'PR.DS', u'DE.AE']} +annotations = {"mitre_attack": ["Credential Access"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 16"], "nist": ["PR.AC", "PR.DS", "DE.AE"]} known_false_positives = Using multiple AWS accounts and roles is perfectly valid behavior. It's suspicious when an account requests privileges of an account it hasn't before. You should validate with the account owner that this is a legitimate request. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - AWS Network Access Control List Created with All Open Ports - Rule] type = detection @@ -1052,9 +1052,9 @@ asset_type = AWS Instance confidence = medium explanation = A network access control list (ACL) is a layer of security for your VPC that acts as a firewall for controlling traffic in and out of one or more subnets. Network ACLs with all open ports have a larger attack surface. This search looks for events within your CloudTrail logs to check if there were any Network ACLs created with ports ranging from 1024 to 65525. This search will create a table comprised of AWS account id, src, user and all parameters of the request made by the user and the server response. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS, version 4.4.0 or later, and configure your CloudTrail inputs. -annotations = {u'mitre_attack': [u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 11'], u'nist': [u'DE.DP', u'DE.AE']} +annotations = {"mitre_attack": ["Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 11"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - AWS Network Access Control List Deleted - Rule] type = detection @@ -1062,9 +1062,9 @@ asset_type = AWS Instance confidence = medium explanation = The search looks for CloudTrail events to detect whether any network ACLs have been deleted and gives you values of error messages and error codes (if any), user details, user source IP, the user who initiated this request, and the name of the event. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. -annotations = {u'mitre_attack': [u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 11'], u'nist': [u'DE.DP', u'DE.AE']} +annotations = {"mitre_attack": ["Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 11"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = It's possible that a user has legitimately deleted a network ACL. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Abnormally High AWS Instances Launched by User - Rule] type = detection @@ -1072,9 +1072,9 @@ asset_type = AWS Instance confidence = medium explanation = In this search, we query CloudTrail logs to look for events where an instance is successfully launched by a particular user. Since we want to detect a high number of instances launched within a short period, we create event buckets for 10-minute windows. We then calculate the total number of instances launched by a particular user, as well as the average and standard deviation values. Assign a threshold_value in the search. Start with 3 (but it will likely need to be tweaked for your environment). The eval function will set the outlier 1 if the number of instances is greater than the average number of instances terminated, added to the multiplied value of threshold and standard deviation. For your reference, we then keep only the outliers and calculate the number of standard deviations away the value is from the average. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. The threshold value should be tuned to your environment. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 13'], u'nist': [u'DE.DP', u'DE.AE']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = Many service accounts configured within an AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify if this search alerted on a human user. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Abnormally High AWS Instances Terminated by User - Rule] type = detection @@ -1082,9 +1082,9 @@ asset_type = AWS Instance confidence = medium explanation = In this search, we query CloudTrail logs to look for events where an instance is successfully terminated by a particular user. Since we want to detect a high number of instances terminated within a short period, we create event buckets for 10-minute windows. We then calculate the total number of instances terminated by a particular user, as well as the average- and standard-deviation values. Assign a threshold_value in the search. Try starting with 3 (but it will likely need to be tweaked for your environment). The eval function will set the outlier to 1 if the number of instances is greater than the average number of instances terminated, added to the multiplied value of threshold and standard deviation. We then filter out outliers with a value of 1 and show only those instance-termination events that happened within the previous 10 minutes. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 13'], u'nist': [u'DE.DP', u'DE.AE']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = Many service accounts configured with your AWS infrastructure are known to exhibit this behavior. Please adjust the threshold values and filter out service accounts from the output. Always verify whether this search alerted on a human user. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Attempt To Add Certificate To Untrusted Store - Rule] type = detection @@ -1092,9 +1092,9 @@ asset_type = Endpoint confidence = high explanation = Attackers will often attempt to disable security tools in order to evade detection. It is also possible for end users to attempt to disable anti-virus or other security tools to circumvent restrictions they encounter while trying to execute other programs. One way malware may accomplish this is by adding the legitimate certificate used to sign the security software to the untrusted certificate store. This will cause the system to no longer trust the software signed with this certificate and disallow it from executing. This search simply looks for the execution of certutil.exe with the parameters -addcert and disallowed, which add a certification to the "untrusted" certificate store. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Disabling Security Tools'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Defense Evasion", "Disabling Security Tools"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = There may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. In such cases, this will typically be done on a large number of systems. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted - Rule] type = detection @@ -1102,9 +1102,9 @@ asset_type = Endpoint confidence = High explanation = This search looks for the process reg.exe with the "add" parameter, which indicates the creation of a new value or modification of an existing value in the registry. In addition, it looks for parameters that specify the registry key to be added or modified, as well as the value of "Unrestricted". The appearance of "ExecutionPolicy" at the beginning of the search is there to optimize the search performance by first looking for that keyword, and then further searching through the matching events for further details. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'PowerShell', u'Scripting'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "PowerShell", "Scripting"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = Administrators may attempt to change the default execution policy on a system for a variety of reasons. However, setting the policy to "Unrestricted" as this search is designed to identify would be unusual. Hits should be reviewed and investigated as appropriate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Attempt To Stop Security Service - Rule] type = detection @@ -1112,9 +1112,9 @@ asset_type = Endpoint confidence = high explanation = This search looks for the processes net.exe and sc.exe with a parameter of "stop". It then searches a list of security-related services included in a lookup file for matches on the command line. Results are subsequently returned in table format. The included lookup file can be modified to update the services to monitor. how_to_implement = You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. The search is shipped with a lookup file, security_services.csv, that can be edited to update the list of services to monitor. This lookup file can be edited directly where it lives in $SPLUNK_HOME/etc/apps/DA-ESS-ContentUpdate/lookups, or via the Splunk console. You should add the names of services an attacker might use on the command line and surround with asterisks (*), so that they work properly when searching the command line. The file should be updated with the names of any services you would like to monitor for attempts to stop the service., -annotations = {u'mitre_attack': [u'Defense Evasion', u'Disabling Security Tools'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Defense Evasion", "Disabling Security Tools"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = None identified. Attempts to disable security-related services should be identified and understood. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Attempted Credential Dump From Registry Via Reg.exe - Rule] type = detection @@ -1122,9 +1122,9 @@ asset_type = Endpoint confidence = High explanation = This search looks for the process reg.exe with the "save" parameter, which specifies a binary export from the registry. In addition, it looks for the keys that contain the hashed credentials, which attackers may retrieve and use for brute-force attacks in order to harvest legitimate credentials. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Credential Access', u'Credential Dumping'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 16'], u'nist': [u'PR.IP', u'PR.AC', u'DE.CM']} +annotations = {"mitre_attack": ["Credential Access", "Credential Dumping"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "nist": ["PR.IP", "PR.AC", "DE.CM"]} known_false_positives = None identified. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Batch File Write to System32 - Rule] type = detection @@ -1132,9 +1132,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at file modifications across your hosts, as well as for evidence of batch files being written to paths that include "system32." This activity is consistent with some SamSam attacks and is, in general, suspicious. how_to_implement = You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Child Processes of Spoolsv.exe - Rule] type = detection @@ -1142,9 +1142,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for child processes of spoolsv.exe, which is associated with the Print Spooler service on Windows. Children of this process typically run under the SYSTEM context. This search should address the POC developed for the Windows local-privilege-escalation exploit announced in September of 2018. The associated vulnerability was assigned CVE-2018-8440. More information is available at https://doublepulsar.com/task-scheduler-alpc-exploit-high-level-analysis-ff08cda6ad4f. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Privilege Escalation', u'Exploitation for Privilege Escalation'], u'kill_chain_phases': [u'Exploitation'], u'cis20': [u'CIS 5', u'CIS 8'], u'nist': [u'PR.AC', u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Privilege Escalation", "Exploitation for Privilege Escalation"], "kill_chain_phases": ["Exploitation"], "cis20": ["CIS 5", "CIS 8"], "nist": ["PR.AC", "PR.PT", "DE.CM"]} known_false_positives = Some legitimate printer-related processes may show up as children of spoolsv.exe. You should confirm that any activity as legitimate and may be added as exclusions in the search. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Clients Connecting to Multiple DNS Servers - Rule] type = detection @@ -1152,9 +1152,9 @@ asset_type = Endpoint confidence = medium explanation = DNS Queries with multiple DNS servers from a single client is unusual and may be indicative of malicious activity. This search works by performing a count by the source of the distinct destinations for the DNS traffic. The search uses the Network_Resolution data model. how_to_implement = This search requires that DNS data is being ingested and populating the Network_Resolution data model. This data can come from DNS logs or from solutions that parse network traffic for this data, such as Splunk Stream or Bro. -annotations = {u'mitre_attack': [u'Command and Control', u'Exfiltration', u'Exfiltration Over Alternative Protocol', u'Commonly Used Port', u'Standard Application Layer Protocol'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 9', u'CIS 12', u'CIS 13'], u'nist': [u'PR.PT', u'DE.AE', u'PR.DS']} +annotations = {"mitre_attack": ["Command and Control", "Exfiltration", "Exfiltration Over Alternative Protocol", "Commonly Used Port", "Standard Application Layer Protocol"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 9", "CIS 12", "CIS 13"], "nist": ["PR.PT", "DE.AE", "PR.DS"]} known_false_positives = It's possible that an enterprise has more than five DNS servers that are configured in a round-robin rotation. Please customize the search, as appropriate. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Common Ransomware Extensions - Rule] type = detection @@ -1162,9 +1162,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at file modifications across your hosts and identifies files with extensions that are commonly associated with the encrypted files generated by ransomware. how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = It is possible for a legitimate file with these extensions to be created. If this is a true ransomware attack, there will be a large number of files created with these extensions. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Common Ransomware Notes - Rule] type = detection @@ -1172,9 +1172,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at file modifications in the Change Analysis data model. It checks modified file names against an included lookup file, which contains the names of note files left behind by ransomware (to inform the victim how they can pay the ransom and retrieve their files). The search returns a list of files with matching names. how_to_implement = You must be ingesting data that records file-system activity from your hosts to populate the Endpoint Filesystem data-model node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = It's possible that a legitimate file could be created with the same name used by ransomware note files. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Create local admin accounts using net.exe - Rule] type = detection @@ -1182,9 +1182,9 @@ asset_type = Endpoint confidence = medium explanation = Net.exe is a built-in Windows command-line tool that can be used to add, display, or modify user accounts. While Microsoft administrators use this tool to manage user groups, threat actors often leverage it to create local admin accounts to maintain persistence. In this search, we are looking for the execution of process net.exe with command-line parameters such as localgroup, add, or user that may correspond to the creation of local admin accounts or setting user/group properties. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface", "Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Administrators often leverage net.exe to create admin accounts. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Create or delete hidden shares using net.exe - Rule] type = detection @@ -1192,9 +1192,9 @@ asset_type = Endpoint confidence = medium explanation = Net.exe is a built-in command-line tool on Windows that can be used to create, delete, and manage shared resources on the computer, both locally and remotely. Though this tool is used by Microsoft administrators to manage the network shares, attackers also leverage it to create and delete hidden file shares by appending "$" after the name of the share. To look for hidden shares, use a regular expression to look for a (name_file_share)$. In this search, we are looking for the command-line execution of net.exe with command-line parameters such as net, share, or delete that may correspond to the creation of hidden shares how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface", "Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Administrators often leverage net.exe to create or delete network shares. You should verify that the activity was intentional and is legitimate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - DNS Query Length With High Standard Deviation - Rule] type = detection @@ -1202,9 +1202,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers often use random, long domain names for their attack infrastructure. This search looks at all the queries observed over the search time frame, and identifies any domains being resolved with names that are greater that 2 times the standard deviation. how_to_implement = To successfully implement this search, you will need to ensure that DNS data is populating the Network_Resolution data model. -annotations = {u'mitre_attack': [u'Command and Control', u'Exfiltration', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 8', u'CIS 12'], u'nist': [u'PR.PT', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Command and Control", "Exfiltration", "Commonly Used Port"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 8", "CIS 12"], "nist": ["PR.PT", "DE.AE", "DE.CM"]} known_false_positives = It's possible there can be long domain names that are legitimate. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule] type = detection @@ -1212,9 +1212,9 @@ asset_type = Endpoint confidence = medium explanation = Clients should be resolving their DNS requests via a trusted DNS server. This search will identify DNS queries being sent to unauthorized DNS servers by comparing the destination and source of the traffic with assets marked as DNS servers. how_to_implement = To successfully implement this search you will need to ensure that DNS data is populating the Network_Resolution data model. It also requires that your DNS servers are identified correctly in the Assets and Identity table of Enterprise Security. -annotations = {u'mitre_attack': [u'Exfiltration', u'Command and Control', u'Defense Evasion', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 1', u'CIS 3', u'CIS 8', u'CIS 12'], u'nist': [u'ID.AM', u'PR.DS', u'PR.IP', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Exfiltration", "Command and Control", "Defense Evasion", "Commonly Used Port"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 1", "CIS 3", "CIS 8", "CIS 12"], "nist": ["ID.AM", "PR.DS", "PR.IP", "DE.AE", "DE.CM"]} known_false_positives = Legitimate DNS activity can be detected in this search. Investigate, verify and update the list of authorized DNS servers as appropriate. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - DNS record changed - Rule] type = detection @@ -1222,9 +1222,9 @@ asset_type = Endpoint confidence = medium explanation = Using a lookup `discover_dns_records` generated by support search "Discover DNS records" we check previous network traffic and make sure the responses have not changed. how_to_implement = To successfully implement this search you will need to ensure that DNS data is populating the `Network_Resolution` data model. It also requires that the `discover_dns_record` lookup table be populated by the included support search "Discover DNS record".

Splunk>Phantom Playbook Integration

If Splunk>Phantom is also configured in your environment, a Playbook called "DNS Hijack Investigation" can be configured to run when any results are found by this detection search. The playbook takes in the DNS record changed and uses Geoip, whois, Censys and PassiveTotal to detect if DNS issuers changed. To use this integration, install the Phantom App for Splunk https://splunkbase.splunk.com/app/3411/, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active.
(Playbook Link:https://my.phantom.us/4.1/playbook/dns-hijack-investigation/).

-annotations = {u'mitre_attack': [u'Exfiltration', u'Command and Control', u'Defense Evasion', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 1', u'CIS 3', u'CIS 8', u'CIS 12'], u'nist': [u'ID.AM', u'PR.DS', u'PR.IP', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Exfiltration", "Command and Control", "Defense Evasion", "Commonly Used Port"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 1", "CIS 3", "CIS 8", "CIS 12"], "nist": ["ID.AM", "PR.DS", "PR.IP", "DE.AE", "DE.CM"]} known_false_positives = Legitimate DNS changes can be detected in this search. Investigate, verify and update the list of provided current answers for the domains in question as appropriate. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Deleting Shadow Copies - Rule] type = detection @@ -1232,9 +1232,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for execution of vssadmin or wmic with both the "delete" and "shadows" parameters passed on the command-line. The two arguments are searched for separately because we can't predict the number of spaces between the words on the command-line. The search will return the number of times this activity was observed, and the times of the first and last event. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8', u'CIS 10'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8", "CIS 10"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = vssadmin.exe and wmic.exe are standard applications shipped with modern versions of windows. They may be used by administrators to legitimately delete old backup copies, although this is typically rare. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect API activity from users without MFA - Rule] type = detection @@ -1242,9 +1242,9 @@ asset_type = AWS Instance confidence = medium explanation = In this search, we query CloudTrail logs and specifically look for events where the multi factor authentication context of the user's session is false which basically means, that the user does not have MFA enabled on AWS. We then filter out all the known AWS service accounts since service accounts typically do not have MFA enabled. The search then creates a table of the first and last time a user without MFA was detected, the values and count of the API calls made, the type of user identity, ARN and the name of the user. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Leverage the support search Create a list of approved AWS service accounts: run it once every 30 days to create a list of service accounts and validate them. -annotations = {u'mitre_attack': [u'Execution'], u'cis20': [u'CIS 16'], u'nist': [u'DE.DP', u'PR.AC']} +annotations = {"mitre_attack": ["Execution"], "cis20": ["CIS 16"], "nist": ["DE.DP", "PR.AC"]} known_false_positives = Many service accounts configured within an AWS infrastructure do not have multi factor authentication enabled. Please ignore the service accounts, if triggered and instead add them to the aws_service_accounts.csv file to fine tune the detection. It is also possible that the search detects users in your environment using Single Sign-On systems, since the MFA is not handled by AWS. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect AWS API Activities From Unapproved Accounts - Rule] type = detection @@ -1252,9 +1252,9 @@ asset_type = AWS Instance confidence = medium explanation = In this search, we are looking for successful API calls via CloudTrail. We filter out events triggered by known users listed in the identity_lookup_expanded lookup file and the service accounts. Once filtered out, we output a table with the event names and count, as well as the first and last time a specific user or service is detected. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. You must also populate the identity_lookup_expanded lookup shipped with the Asset and Identity framework to be able to look up users in your identity table in Enterprise Security (ES). Leverage the support search called "Create a list of approved AWS service accounts": run it once every 30 days to create and validate a list of service accounts. -annotations = {u'mitre_attack': [u'Credential Access', u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 16'], u'nist': [u'DE.DP', u'DE.CM', u'PR.AC', u'ID.AM']} +annotations = {"mitre_attack": ["Credential Access", "Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 16"], "nist": ["DE.DP", "DE.CM", "PR.AC", "ID.AM"]} known_false_positives = It's likely that you'll find activity detected by users/service accounts that are not listed in the identity_lookup_expanded or aws_service_accounts.csv file. If the user is a legitimate service account, update the aws_service_accounts.csv table with that entry. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Activity Related to Pass the Hash Attacks - Rule] type = detection @@ -1262,9 +1262,9 @@ asset_type = Endpoint confidence = low explanation = To detect pass the hash activity, we look at all events with event code 4624 or 4625 that specify a logon type 3 (network logons). We are looking for the NtLmSsP account, with a key length set to 0. These indicate lower level protocols that are typically used through Pass the Hash (WMI, SMB, etc.). The search also filters out events with an account name of 'Anonymous' to help reduce false positives. how_to_implement = To successfully implement this search, you must ingest your Windows Security Event logs and leverage the latest TA for Windows. -annotations = {u'mitre_attack': [u'Lateral Movement', u'Pass the Hash'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 16'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Lateral Movement", "Pass the Hash"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Legitimate logon activity by authorized NTLM systems may be detected by this search. Please investigate as appropriate. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule] type = detection @@ -1272,9 +1272,9 @@ asset_type = Endpoint confidence = high explanation = This search gathers all the answers to each system's DNS query, then filters for queries that have sub domains extracted from the EvilGinx toolkit. It will then run a regex to extract `domain` from the query and remove that from the detection if it is listed in the `domains.csv` how_to_implement = You need to ingest data from your DNS logs. Specifically you must ingest the domain that is being queried and the IP of the host originating the request. Ideally, you should also be ingesting the answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You will have to add legitimate domain names to the `domains.csv` file shipped with the app -annotations = {u'mitre_attack': [u'Exfiltration', u'Command and Control', u'Defense Evasion', u'Commonly Used Port'], u'kill_chain_phases': [u'Delivery', u'Actions on Objectives', u'Command and Control'], u'cis20': [u'CIS 1', u'CIS 3', u'CIS 8', u'CIS 12'], u'nist': [u'ID.AM', u'PR.DS', u'PR.IP', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Exfiltration", "Command and Control", "Defense Evasion", "Commonly Used Port"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Command and Control"], "cis20": ["CIS 1", "CIS 3", "CIS 8", "CIS 12"], "nist": ["ID.AM", "PR.DS", "PR.IP", "DE.AE", "DE.CM"]} known_false_positives = If a known good domain is not listed in the known_domains.csv file, then the search could give you false postives. Please update that lookup file to filter out legitimate DNS requests -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Detect Excessive Account Lockouts From Endpoint - Rule] type = detection @@ -1282,9 +1282,9 @@ asset_type = Windows confidence = low explanation = This search queries the `Change.All_Changes` datamodel under the nodename is `Account_Management` , where the result is "lockout", which indicates that an account has been locked out. It then counts the number of times an endpoint has caused an account lockout within a four hour window and displays those hosts with a count greater than or equal to five. how_to_implement = You must ingest your Windows security event logs in the `Change` datamodel under the nodename is `Account_Management`, for this search to execute successfully. Please consider updating the cron schedule and the count of lockouts you want to monitor, according to your environment.

Splunk>Phantom Playbook Integration

If Splunk>Phantom is also configured in your environment, a Playbook called "Excessive Account Lockouts Enrichment and Response" can be configured to run when any results are found by this detection search. The Playbook executes the Contextual and Investigative searches in this Story, conducts additional information gathering on Windows endpoints, and takes a response action to shut down the affected endpoint. To use this integration, install the Phantom App for Splunk https://splunkbase.splunk.com/app/3411/, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active.
(Playbook Link:https://my.phantom.us/4.1/playbook/excessive-account-lockouts-enrichment-and-response/).

-annotations = {u'mitre_attack': [u'Valid Accounts'], u'cis20': [u'CIS 16'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Valid Accounts"], "cis20": ["CIS 16"], "nist": ["PR.IP"]} known_false_positives = It's possible that a widely used system, such as a kiosk, could cause a large number of account lockouts. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect Excessive User Account Lockouts - Rule] type = detection @@ -1292,9 +1292,9 @@ asset_type = Windows confidence = medium explanation = This search queries the `Change.All_Changes` datamodel under the nodename is `Account_Management` , where the result is "lockout", which indicates that an account has been locked out. It then counts the number of times a user has caused an account lockout within a four hour window and displays those users with a count greater than or equal to five. how_to_implement = ou must ingest your Windows security event logs in the `Change` datamodel under the nodename is `Account_Management`, for this search to execute successfully. Please consider updating the cron schedule and the count of lockouts you want to monitor, according to your environment. -annotations = {u'mitre_attack': [u'Valid Accounts'], u'cis20': [u'CIS 16'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Valid Accounts"], "cis20": ["CIS 16"], "nist": ["PR.IP"]} known_false_positives = It is possible that a legitimate user is experiencing an issue causing multiple account login failures leading to lockouts. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect Large Outbound ICMP Packets - Rule] type = detection @@ -1302,9 +1302,9 @@ asset_type = Endpoint confidence = medium explanation = This search works by looking at fields in the Network_Traffic data model, which is populated by various firewalls and passive networking monitoring technologies. Specifically, the search looks for ICMP packets larger than 1,000 bytes with a destination that is external to your organization. how_to_implement = In order to run this search effectively, we highly recommend that you leverage the Assets and Identity framework. It is important that you have a good understanding of how your network segments are designed and that you are able to distinguish internal from external address space. Add a category named internal to the CIDRs that host the company's assets in the assets_by_cidr.csv lookup file, which is located in $SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/. More information on updating this lookup can be found here: https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Addassetandidentitydata. This search also requires you to be ingesting your network traffic and populating the Network_Traffic data model -annotations = {u'mitre_attack': [u'Command and Control', u'Standard Non-Application Layer Protocol'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 9', u'CIS 12'], u'nist': [u'DE.AE']} +annotations = {"mitre_attack": ["Command and Control", "Standard Non-Application Layer Protocol"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 9", "CIS 12"], "nist": ["DE.AE"]} known_false_positives = ICMP packets are used in a variety of ways to help troubleshoot networking issues and ensure the proper flow of traffic. As such, it is possible that a large ICMP packet could be perfectly legitimate. If large ICMP packets are associated with command and control traffic, there will typically be a large number of these packets observed over time. If the search is providing a large number of false positives, you can modify the search to adjust the byte threshold or whitelist specific IP addresses, as necessary. -providing_technologies = [u'Bro', u'Splunk Stream', u'Palo Alto Firewall'] +providing_technologies = ["Bro", "Splunk Stream", "Palo Alto Firewall"] [savedsearch://ESCU - Detect Long DNS TXT Record Response - Rule] type = detection @@ -1312,9 +1312,9 @@ asset_type = Endpoint confidence = medium explanation = This search uses the Network_Resolution data model and gathers all the answers to DNS queries for TXT records. The query then looks at the answer section and calculates the length of the answer. The search will then return information for those responses that exceed 100 characters in length. how_to_implement = To successfully implement this search you need to ingest data from your DNS logs, or monitor DNS traffic using Stream, Bro or something similar. Specifically, this query requires that the DNS data model is populated with information regarding the DNS record type that is being returned as well as the data in the answer section of the protocol. -annotations = {u'mitre_attack': [u'Command and Control', u'Exfiltration', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 8', u'CIS 12', u'CIS 13'], u'nist': [u'PR.DS', u'PR.PT', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Command and Control", "Exfiltration", "Commonly Used Port"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 8", "CIS 12", "CIS 13"], "nist": ["PR.DS", "PR.PT", "DE.AE", "DE.CM"]} known_false_positives = It's possible that legitimate TXT record responses can be long enough to trigger this search. You can modify the packet threshold for this search to help mitigate false positives. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Detect Mimikatz Via PowerShell And EventCode 4663 - Rule] type = detection @@ -1322,9 +1322,9 @@ asset_type = Windows confidence = medium explanation = This search looks for Windows Event Code(signature_id) 4663 (object access), where the process performing the access is PowerShell.exe, the target process of the access is lsass.exe, and the access mask is given as 0x10. This is consistent with the use of PowerShell to execute Mimikatz using sekurlsa::logonpasswords. It will return the host where the activity occurred, the process and associated id, the enabled privilege, and the message in the event. how_to_implement = You must be ingesting Windows Security logs. You must also enable the account change auditing here: http://docs.splunk.com/Documentation/Splunk/7.0.2/Data/MonitorWindowseventlogdata. Additionally, this search requires you to enable your Group Management Audit Logs in your Local Windows Security Policy and to be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/. Finally, please make sure that the local administrator group name is "Administrators" to be able to look for the right group membership changes. -annotations = {u'mitre_attack': [u'Credential Access', u'Credential Dumping'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 16'], u'nist': [u'PR.IP', u'PR.AC', u'DE.CM']} +annotations = {"mitre_attack": ["Credential Access", "Credential Dumping"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "nist": ["PR.IP", "PR.AC", "DE.CM"]} known_false_positives = The activity may be legitimate. PowerShell is often used by administrators to perform various tasks, and it's possible this event could be generated in those cases. In these cases, false positives should be fairly obvious and you may need to tweak the search to eliminate noise. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule] type = detection @@ -1332,9 +1332,9 @@ asset_type = Windows confidence = medium explanation = This search looks for Windows Event Code(signature_id) 4703 (token right adjusted), where the process requesting the token change is PowerShell.exe and the requested privilege is "SeDebugPrivilege". This is consistent with the use of PowerShell to execute Mimikatz using sekurlsa::logonpasswords. It will return the host where the activity occurred, the process and associated id, the enabled privilege, and the message in the event. how_to_implement = You must be ingesting Windows Security logs. You must also enable the account change auditing here: http://docs.splunk.com/Documentation/Splunk/7.0.2/Data/MonitorWindowseventlogdata. Additionally, this search requires you to enable your Group Management Audit Logs in your Local Windows Security Policy and to be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/. Finally, please make sure that the local administrator group name is "Administrators" to be able to look for the right group membership changes. -annotations = {u'mitre_attack': [u'Credential Access', u'Credential Dumping'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 16'], u'nist': [u'PR.IP', u'PR.AC', u'DE.CM']} +annotations = {"mitre_attack": ["Credential Access", "Credential Dumping"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 16"], "nist": ["PR.IP", "PR.AC", "DE.CM"]} known_false_positives = The activity may be legitimate. PowerShell is often used by administrators to perform various tasks, and it's possible this event could be generated in those cases. In these cases, false positives should be fairly obvious and you may need to tweak the search to eliminate noise. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect New Local Admin account - Rule] type = detection @@ -1342,9 +1342,9 @@ asset_type = Windows confidence = medium explanation = This search looks for Windows Event Code 4720 (account creation) and 4732 (account added to a security-enabled local group), where the group name is "Administrators", and determines whether they are generated for the same user's Security ID within three hours of each other. It will return the user account that was added, the Security ID, the group name to which the user was added, the account name of the user who initiated the action, and the subsequent message returned. how_to_implement = You must be ingesting Windows Security logs. You must also enable the account change auditing here:http://docs.splunk.com/Documentation/Splunk/7.0.2/Data/MonitorWindowseventlogdata. Additionally, this search requires you to enable your Group Management Audit Logs in your Local Windows Security Policy and to be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/. Finally, please make sure that the local administrator group name is "Administrators" to be able to look for the right group membership changes. -annotations = {u'mitre_attack': [u'Valid Accounts', u'Defense Evasion', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives', u'Command and Control'], u'cis20': [u'CIS 16'], u'nist': [u'PR.AC', u'DE.CM']} +annotations = {"mitre_attack": ["Valid Accounts", "Defense Evasion", "Persistence"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "cis20": ["CIS 16"], "nist": ["PR.AC", "DE.CM"]} known_false_positives = The activity may be legitimate. For this reason, it's best to verify the account with an administrator and ask whether there was a valid service request for the account creation. If your local administrator group name is not "Administrators", this search may generate an excessive number of false positives -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect New Login Attempts to Routers - Rule] type = detection @@ -1352,9 +1352,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers will often attempt to compromise network devices such as routers for a variety of nefarious purposes, including modifying VPN settings or re-routing network traffic. Typically, only a relatively small number of user accounts log into these devices on a regular basis. This search identifies 'new' connections to your routers by checking to see if a similar login was made in the last 30 days. Routers are identified by checking the IP address against those categorized as a "router" in the ES assets and identity framework. how_to_implement = To successfully implement this search, you must ensure the network router devices are categorized as "router" in the Assets and identity table. You must also populate the Authentication data model with logs related to users authenticating to routing infrastructure. -annotations = {u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 11'], u'nist': [u'PR.PT', u'PR.AC', u'PR.IP']} +annotations = {"kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 11"], "nist": ["PR.PT", "PR.AC", "PR.IP"]} known_false_positives = Legitimate router connections may appear as new connections -providing_technologies = [u'Active Directory', u'Palo Alto Firewall'] +providing_technologies = ["Active Directory", "Palo Alto Firewall"] [savedsearch://ESCU - Detect New Open S3 buckets - Rule] type = detection @@ -1362,9 +1362,9 @@ asset_type = S3 Bucket confidence = medium explanation = This search queries CloudTrail logs for events with S3 bucket access controls given to the "All Users" group, which allows anyone in the world access to the resource. This search generates a table displaying the time when the bucket was made public, the permission of the S3 bucket, the bucket name, and the ARN of the user who created the bucket. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), and then configure your CloudTrail inputs. The threshold value should be tuned to your environment. -annotations = {u'mitre_attack': [u'Execution', u'Initial Access', u'Exfiltration'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 13'], u'nist': [u'PR.DS', u'PR.AC', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Initial Access", "Exfiltration"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 13"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a public bucket for a specific purpose. That said, AWS strongly advises against granting full control to the "All Users" group. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Oulook.exe writing a .zip file - Rule] type = detection @@ -1372,9 +1372,9 @@ asset_type = Endpoint confidence = high explanation = In this search, we are essentially trying to detect if outlook.exe is writing a `.zip` file to the disk. The way this search would run is, it will execute the the subsearch first which looks for all .zip files being written to the disk and outputs a crucial field "process_id", that we use the main search to check if that process_id belongs to a process_name of outlook.exe. The search uses a join command to essentially give you an end result of the first and last time that zip file was written by outlook.exe, the dest and user logged on the system, the hash value and the complete path to the zip file on disk how_to_implement = You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or endpoint data sources, such as Sysmon. -annotations = {u'mitre_attack': [u'Spearphishing Attachment'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 7', u'CIS 8'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Spearphishing Attachment"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 7", "CIS 8"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = It is not uncommon for outlook to write legitimate zip files to the disk. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect Outbound SMB Traffic - Rule] type = detection @@ -1382,9 +1382,9 @@ asset_type = Endpoint confidence = medium explanation = In this search, we are looking for the network connections that were not blocked by the firewall and that are destined for destination port 139 or 445. We then filter out events that have Classless Inter-Domain Routing (CIDR) blocks categorized as internal in the assets_by_cidr.csv lookup file which is located in $SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/. Since we are only looking for outbound traffic from the hosts made to the Internet, we filter out traffic whose destination IP address is private. how_to_implement = In order to run this search effectively, we highly recommend that you leverage the Assets and Identity framework. It is important that you have good understanding of how your network segments are designed, and be able to distinguish internal from external address space. Add a category named internal to the CIDRs that host the company's assets in assets_by_cidr.csv lookup file, which is located in $SPLUNK_HOME/etc/apps/SA-IdentityManagement/lookups/. More information on updating this lookup can be found here: https://docs.splunk.com/Documentation/ES/5.0.0/Admin/Addassetandidentitydata. This search also requires you to be ingesting your network traffic and populating the Network_Traffic data model -annotations = {u'mitre_attack': [u'Commonly Used Port', u'Credential Access', u'Lateral Movement'], u'kill_chain_phases': [u'Actions on Objectives', u'Command and Control'], u'cis20': [u'CIS 12'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Commonly Used Port", "Credential Access", "Lateral Movement"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "cis20": ["CIS 12"], "nist": ["DE.CM"]} known_false_positives = It is likely that the outbound Server Message Block (SMB) traffic is legitimate, if the company's internal networks are not well-defined in the Assets and Identity Framework. Categorize the internal CIDR blocks as internal in the lookup file to avoid creating notable events for traffic destined to those CIDR blocks. Any other network connection that is going out to the Internet should be investigated and blocked. Best practices suggest preventing external communications of all SMB versions and related protocols at the network boundary. -providing_technologies = [u'Bro', u'Splunk Stream'] +providing_technologies = ["Bro", "Splunk Stream"] [savedsearch://ESCU - Detect Path Interception By Creation Of program.exe - Rule] type = detection @@ -1392,9 +1392,9 @@ asset_type = confidence = medium explanation = This search queries the Endpoint file-system data model node to list out all the values of destination machines, as well as the values of file hashes and file paths that have the file "program.exe" in the C: drive. Path interception occurs when an executable is placed in a specific path so that it is executed by an application instead of by the intended target. In this case, applications vulnerable to path interception (because of unquoted service paths with spaces in Windows registry) allow attackers to execute maliciously crafted program.exes. how_to_implement = You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data model node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file system reads and writes. -annotations = {u'mitre_attack': [u'Privilege Escalation', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Privilege Escalation", "Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = It is unlikely that a normal user may create and place this file in the C: drive. Confirm with the user. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect Prohibited Applications Spawning cmd.exe - Rule] type = detection @@ -1402,9 +1402,9 @@ asset_type = Endpoint confidence = medium explanation = Obtaining access to the Command-Line Interface (CLI) is typically a primary attacker goal. Once an attacker has obtained the ability to execute code on a target system, they will often further manipulate the system via commands passed to the CLI. It is also unusual for many applications to spawn a command shell during normal operation, while it is often observed if an application has been compromised in some way. As such, it is often beneficial to look for cmd.exe being executed by processes that are often targeted for exploitation, or that would not spawn cmd.exe in any other circumstances. A lookup file is provided to easily modify the processes that are being watched for execution of cmd.exe. how_to_implement = You must be ingesting data that records process activity from your hosts and populates the Endpoint data model with the resultant dataset. This search includes a lookup file, prohibited_apps_launching_cmd.csv, that contains a list of processes that should not be spawning cmd.exe. You can modify this lookup to better suit your environment. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface'], u'kill_chain_phases': [u'Exploitation'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface"], "kill_chain_phases": ["Exploitation"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = There are circumstances where an application may legitimately execute and interact with the Windows command-line interface. Investigate and modify the lookup file, as appropriate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect PsExec With accepteula Flag - Rule] type = detection @@ -1412,9 +1412,9 @@ asset_type = Endpoint confidence = medium explanation = In this search, we are looking for the PsExec process with accepteula on the command line. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Administrators can leverage PsExec for accessing remote systems and might pass accepteula as an argument if they are running this tool for the first time. However, it is not likely that you'd see multiple occurrences of this event on a machine -providing_technologies = [u'Sysmon'] +providing_technologies = ["Sysmon"] [savedsearch://ESCU - Detect Rare Executables - Rule] type = detection @@ -1422,9 +1422,9 @@ asset_type = Endpoint confidence = medium explanation = This search first executes the subsearch and counts all of your processes to determine the 10 most rare (the limit set is 10). It then filters out whitelisted processes and outputs the first and last time a rare process was encountered, the destination where the process is running, the count of occurrences, and the users who initiated the processes. how_to_implement = To successfully implement this search, you must be ingesting data that records process activity from your hosts and populating the endpoint data model with the resultant dataset. The macro filter_rare_process_whitelist searches two lookup files to whitelist your processes. These consist of rare_process_whitelist_default.csv and rare_process_whitelist_local.csv. To add your own processes to the whitelist, add them to rare_process_whitelist_local.csv. If you wish to remove an entry from the default lookup file, you will have to modify the macro itself to set the whitelist value for that process to false. You can modify the limit parameter and search scheduling to better suit your environment. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Installation', u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 2', u'CIS 8'], u'nist': [u'ID.AM', u'PR.PT', u'PR.DS', u'DE.CM']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Installation", "Command and Control", "Actions on Objectives"], "cis20": ["CIS 2", "CIS 8"], "nist": ["ID.AM", "PR.PT", "PR.DS", "DE.CM"]} known_false_positives = Some legitimate processes may be only rarely executed in your environment. As these are identified, update rare_process_whitelist_local.csv to filter them out of your search results. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect S3 access from a new IP - Rule] type = detection @@ -1432,9 +1432,9 @@ asset_type = S3 Bucket confidence = low explanation = Here the subsearch executes first and returns all successful S3 bucket-access attempts (HTTP code "200") within the last hour. It groups the results by the earliest and latest times it has seen a remote IP accessing a particular bucket. It appends this information to the historical data from the lookup file and then recalculates the firstTime and lastTime field for each remote IP accessing an S3 bucket. Next, it returns only those remote IP addresses that have first been seen accessing a specific bucket within the past hour. This is combined with the main search to return the time, bucket name, source IP, city, and country operations performed, as well as the requested URI of the resource how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your S3 access logs' inputs. This search works best when you run the "Previously Seen S3 Bucket Access by Remote IP" support search once to create a history of previously seen remote IPs and bucket names. -annotations = {u'mitre_attack': [u'Execution', u'Exfiltration'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 13', u'CIS 14'], u'nist': [u'PR.DS', u'PR.AC', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Exfiltration"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 13", "CIS 14"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} known_false_positives = S3 buckets can be accessed from any IP, as long as it can make a successful connection. This will be a false postive, since the search is looking for a new IP within the past hour -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Spike in AWS API Activity - Rule] type = detection @@ -1442,9 +1442,9 @@ asset_type = AWS Instance confidence = medium explanation = This search and its corresponding subsearch run through a series of steps, as per the following:
  1. Retrieves all the AWS CloudTrail log entries that have recorded AWS API calls.
  2. Kicks off a subsearch that retrieves the same data and pulls out the ARN into a more friendly format.
  3. Counts the number of API calls per ARN.
  4. Loads the cache file that contains the number of data points, the count from the latest hour, the API call average, and the standard deviation for each ARN.
  5. Drops the count from the latest hour, since it is not necessary, and merges the rest of the data with the results of the stats command.
  6. Renames apiCalls as latestCount.
  7. Calculates the new average value for each ARN with the latest count, weighting the past much more heavily than the current hour. It does the same for the standard deviation--weighting the past more heavily than the current.
  8. Updates the cache file with the latest results.
  9. Sets the minimum threshold for the number of data points and sets the number of standard deviations away from the mean it must be to be considered a spike.
  10. Makes a determination regarding whether or not the current count is a spike by checking to see if the minimum data-point threshold has been met and the count is a sufficient number of standard deviations away from the average.
  11. Filters out anything that it determines is not a spike and returns the list of ARNs to the main search.
The main search subsequently gets the names of all the API calls, the number of unique API calls, and the total number of API calls for each of these ARNs. Finally, it looks up the average and standard deviation and returns both the average and the number of standard deviations the spike is from the average. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. You can modify dataPointThreshold and deviationThreshold to better fit your environment. The dataPointThreshold variable is the minimum number of data points required to have a statistically significant amount of data to determine. The deviationThreshold variable is the number of standard deviations away from the mean that the value must be to be considered a spike. -annotations = {u'mitre_attack': [u'Credential Access', u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 16'], u'nist': [u'DE.DP', u'DE.CM', u'PR.AC']} +annotations = {"mitre_attack": ["Credential Access", "Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 16"], "nist": ["DE.DP", "DE.CM", "PR.AC"]} known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Spike in Network ACL Activity - Rule] type = detection @@ -1452,9 +1452,9 @@ asset_type = AWS Instance confidence = medium explanation = This search and its corresponding subsearch run through the following series of steps:
  1. Retrieve all the AWS CloudTrail log entries that have recorded AWS API calls specifically for creating/modifying/replacing network Access Control Lists (ACLs).
  2. Kick off a subsearch that retrieves the same data and pulls out the ARN into a more friendly format.
  3. Count the number of API calls per Amazon Resource Name (ARN).
  4. Load the cache file that contains the number of data points, the count from the latest hour, the API call average, and the standard deviation for each ARN.
  5. Drop the count from the latest hour, since it is not necessary, and merge the rest of the data with the results of the stats command.
  6. Rename apiCalls as latestCount.
  7. Calculate the new average value for each ARN with the latest count, weighting the past much more heavily than the current hour. They do the same for the standard deviation--weighting the past more heavily than the current.
  8. Update the cache file with the latest results.
  9. Set the minimum threshold for the number of data points and set the number of standard deviations away from the mean it must be to be considered a spike.
  10. Make a determination regarding whether or not the current count is a spike by checking to see if the minimum data-point threshold has been met and the count is a sufficient number of standard deviations away from the average.
  11. Filter out anything that it determines is not a spike and return the list of ARNs to the main search.
The main search subsequently gets the names of all the API calls, the number of unique API calls, and the total number of API calls for each of these ARNs. Finally, it looks up the average and standard deviation and returns both the average and the number of standard deviations the spike is from the average. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. You can modify dataPointThreshold and deviationThreshold to better fit your environment. The dataPointThreshold variable is the minimum number of data points required to have a statistically significant amount of data to determine. The deviationThreshold variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of Network ACL Activity by ARN" support search once to create a lookup file of previously seen Network ACL Activity. To add or remove API event names related to network ACLs, edit the macro NetworkACLEvents. -annotations = {u'mitre_attack': [u'Persistence', u'Exfiltration'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 12', u'CIS 11'], u'nist': [u'DE.DP', u'DE.CM', u'PR.AC']} +annotations = {"mitre_attack": ["Persistence", "Exfiltration"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 12", "CIS 11"], "nist": ["DE.DP", "DE.CM", "PR.AC"]} known_false_positives = The false-positive rate may vary based on the values ofdataPointThreshold and deviationThreshold. Please modify this according the your environment. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Spike in S3 Bucket deletion - Rule] type = detection @@ -1462,9 +1462,9 @@ asset_type = S3 Bucket confidence = medium explanation = This search and its corresponding subsearch run through the following series of steps:
  1. Retrieve all the AWS CloudTrail log entries that have recorded AWS API calls specifically for deletion of S3 buckets.
  2. Kick off a subsearch that retrieves the same data and pulls out and converts the ARN into a more friendly format.
  3. Count the number of API calls per ARN.
  4. Load the cache file that contains the number of data points, the count from the latest hour, the API call average, and the standard deviation for each ARN.
  5. Drop the count from the latest hour, since it is unnecessary, and merge the rest of the data with the results of the stats command.
  6. Rename apiCalls as latestCount.
  7. Calculate the new average value for each ARN with the latest count, weighting the past more heavily than the current hour. It does the same for the standard deviation—weighting the past more heavily than the current.
  8. Update the cache file with the latest results.
  9. Set the minimum threshold for the number of data points and the number of standard deviations away from the mean it must be to be considered a spike.
  10. Make a determination regarding whether or not the current count is a spike by checking to see if the minimum data-point threshold has been met and if the count is a sufficient number of standard deviations away from the average.
  11. Filter out anything that it determines is not a spike and returns the list of ARNs to the main search.
The main search subsequently gets the names of the deleted S3 buckets, the number of unique API calls, and the total number of API calls for each of these user ARNs. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. You can modify dataPointThreshold and deviationThreshold to better fit your environment. The dataPointThreshold variable is the minimum number of data points required to have a statistically significant amount of data to determine. The deviationThreshold variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of S3 Bucket deletion activity by ARN" support search once to create a baseline of previously seen S3 bucket-deletion activity. -annotations = {u'mitre_attack': [u'Credential Access', u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 13'], u'nist': [u'DE.DP', u'DE.CM', u'PR.AC']} +annotations = {"mitre_attack": ["Credential Access", "Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 13"], "nist": ["DE.DP", "DE.CM", "PR.AC"]} known_false_positives = Based on the values ofdataPointThreshold and deviationThreshold, the false positive rate may vary. Please modify this according the your environment. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Spike in Security Group Activity - Rule] type = detection @@ -1472,9 +1472,9 @@ asset_type = AWS Instance confidence = medium explanation = This search and its corresponding subsearch run through the following series of steps:
  1. Retrieves all the AWS CloudTrail log entries that have recorded AWS API calls specifically for security groups.
  2. Kicks off a subsearch that retrieves the same data and pulls out the ARN into a more friendly format.
  3. Counts the number of API calls per ARN.
  4. Loads the cache file that contains the number of data points, the count from the latest hour, the API call average, and the standard deviation for each ARN.
  5. Drops the count from the latest hour, since it is not necessary, and merges the rest of the data with the results of the stats command.
  6. Renames apiCalls as latestCount.
  7. Calculates the new average value for each ARN with the latest count, weighting the past much more heavily than the current hour. It does the same for the standard deviation--weighting the past more heavily than the current.
  8. Updates the cache file with the latest results.
  9. Sets the minimum threshold for the number of data points and sets the number of standard deviations away from the mean it must be to be considered a spike.
  10. Makes a determination regarding whether or not the current count is a spike by checking to see if the minimum data-point threshold has been met and the count is a sufficient number of standard deviations away from the average.
  11. Filters out anything that it determines is not a spike and returns the list of ARNs to the main search.
The main search subsequently gets the names of all the API calls, the number of unique API calls, and the total number of API calls for each of these ARNs. Finally, it looks up the average and standard deviation and returns both the average and the number of standard deviations the spike is from the average. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. You can modify dataPointThreshold and deviationThreshold to better fit your environment. The dataPointThreshold variable is the minimum number of data points required to have a statistically significant amount of data to determine. The deviationThreshold variable is the number of standard deviations away from the mean that the value must be to be considered a spike.This search works best when you run the "Baseline of Security Group Activity by ARN" support search once to create a history of previously seen Security Group Activity. To add or remove API event names for security groups, edit the macro securityGroupAPIs. -annotations = {u'mitre_attack': [u'Credential Access', u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 16'], u'nist': [u'DE.DP', u'DE.CM', u'PR.AC']} +annotations = {"mitre_attack": ["Credential Access", "Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 16"], "nist": ["DE.DP", "DE.CM", "PR.AC"]} known_false_positives = Based on the values ofdataPointThreshold and deviationThreshold, the false positive rate may vary. Please modify this according the your environment. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule] type = detection @@ -1482,9 +1482,9 @@ asset_type = AWS Instance confidence = medium explanation = This search retrieves all the VPC Flow log entries that have recorded a blocked outbound network connection originating from your AWS environment. Then it kicks off a subsearch, which looks at the same data and performs the following series of steps:
  1. Counts the number of blocked outbound connections by each source IP
  2. Loads the cache file that contains the number of data points, the count from the latest hour, the average blocked connections, and the standard deviation for each source IP.
  3. Drops the count from the latest hour, since it is not necessary, and merges the rest of the data with the results of the stats command.
  4. Renames numberOfBlockedConnections as latestCount.
  5. Calculates the new average value for each source IP with the latest count, weighting the past much more heavily than the current hour. It does the same for the standard deviation, weighting the past more heavily than the current.
  6. Updates the cache file with the latest results.
  7. Sets the minimum threshold for the number of data points and sets the number of standard deviations away from the mean it must be to be considered a spike.
  8. Makes a determination regarding whether or not the current count is a spike by checking to see if the minimum data-point threshold has been met and the count is a sufficient number of standard deviations away from the average.
  9. Filters out anything that it determines is not a spike and returns the list of source IPs to the main search.
The main search subsequently gets the list of all destination IPs for which the traffic was blocked, the network interface ID, the number of unique destination IP, and the total number of blocked connections for each of these source IP addresses. Finally, it looks up the average and standard deviation and returns both the average and the number of standard deviations the spike is from the average. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your VPC Flow logs. You can modify dataPointThreshold and deviationThreshold to better fit your environment. The dataPointThreshold variable is the number of data points required to meet the definition of "spike." The deviationThreshold variable is the number of standard deviations away from the mean that the value must be to be considered a spike. This search works best when you run the "Baseline of Blocked Outbound Connection" support search once to create a history of previously seen blocked outbound connections. -annotations = {u'mitre_attack': [u'Exfiltration', u'Command and Control'], u'kill_chain_phases': [u'Actions on Objectives', u'Command and Control'], u'cis20': [u'CIS 11'], u'nist': [u'DE.AE', u'DE.CM', u'PR.AC']} +annotations = {"mitre_attack": ["Exfiltration", "Command and Control"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "cis20": ["CIS 11"], "nist": ["DE.AE", "DE.CM", "PR.AC"]} known_false_positives = The false-positive rate may vary based on the values ofdataPointThreshold and deviationThreshold. Additionally, false positives may result when AWS administrators roll out policies enforcing network blocks, causing sudden increases in the number of blocked outbound connections. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect USB device insertion - Rule] type = detection @@ -1492,9 +1492,9 @@ asset_type = Endpoint confidence = low explanation = USB is a common attack vector for delivering or propagating malicious code, or the exfiltration of data. Your corporation may have a policy of not allowing removable media at all, or may only allow approved media to be used on specific hosts by specific users. By logging USB activity from Windows and other endpoints gathered using the Universal Forwarder, you can gain an understanding of what systems might be vulnerable to attack via removable media, or what users might need additional security training. This search is looking for event_id 4656 for failure and 4663 for successful USB read/write attempts from Windows Security Event logs, which is the event code generated when a files are read from and written to a removable storage device how_to_implement = To successfully implement this search, you must ingest Windows Security Event logs and track event code 4663 and 4656. Ensure that the field from the event logs is being mapped to the result_id field in the Change_Analysis data model. To minimize the alert volume, this search leverages the Assets and Identity framework to filter out events from those assets not marked high priority in the Enterprise Security Assets and Identity Framework. -annotations = {u'mitre_attack': [u'Exfiltration'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 13'], u'nist': [u'PR.PT', u'PR.DS']} +annotations = {"mitre_attack": ["Exfiltration"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 13"], "nist": ["PR.PT", "PR.DS"]} known_false_positives = Legitimate USB activity will also be detected. Please verify and investigate as appropriate. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Detect Unauthorized Assets by MAC address - Rule] type = detection @@ -1502,9 +1502,9 @@ asset_type = Infrastructure confidence = medium explanation = This search requires you to leverage the Enterprise Security Assets and Identity framework to populate assets_by_str.csv. Once the assets_by_str.csv is populated, we then query your DHCP logs to detect unknown systems connecting to your network. More documentation is available at: http://docs.splunk.com/Documentation/ES/4.7.1/Admin/Verifyassetandidentitydata. how_to_implement = This search uses the Network_Sessions data model shipped with Enterprise Security. It leverages the Assets and Identity framework to populate the assets_by_str.csv file located in SA-IdentityManagement, which will contain a list of known authorized organizational assets including their MAC addresses. Ensure that all inventoried systems have their MAC address populated. -annotations = {u'mitre_attack': [u'Defense Evasion'], u'kill_chain_phases': [u'Reconnaissance', u'Delivery', u'Actions on Objectives'], u'cis20': [u'CIS 1'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Defense Evasion"], "kill_chain_phases": ["Reconnaissance", "Delivery", "Actions on Objectives"], "cis20": ["CIS 1"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = This search might be prone to high false positives. Please consider this when conducting analysis or investigations. Authorized devices may be detected as unauthorized. If this is the case, verify the MAC address of the system responsible for the false positive and add it to the Assets and Identity framework with the proper information. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Detect Use of cmd.exe to Launch Script Interpreters - Rule] type = detection @@ -1512,9 +1512,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers often leverage various scripting languages to execute their attacks. In a Windows environment, the Windows Script Host is the tool that interprets the scripts and is included in all modern versions of Windows. The Windows Script Host is available as a command-line tool called "cscript.exe" or "wscript.exe." To detect this behavior, the search looks for process-creation events for cscript.exe or wscript.exe with a parent process of cmd.exe. The search will return the count, the first and last times this behavior was seen on a destination machine, and user and process information. how_to_implement = To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface'], u'kill_chain_phases': [u'Exploitation'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface"], "kill_chain_phases": ["Exploitation"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Some legitimate applications may exhibit this behavior. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule] type = detection @@ -1522,9 +1522,9 @@ asset_type = Web Server confidence = medium explanation = This search returns the number of times a URL associated with this type of JexBoss probe is observed. how_to_implement = You must be ingesting data from the web server or network traffic that contains web specific information, and populating the Web data model. -annotations = {u'mitre_attack': [u'Discovery', u'System Information Discovery'], u'kill_chain_phases': [u'Reconnaissance']} +annotations = {"mitre_attack": ["Discovery", "System Information Discovery"], "kill_chain_phases": ["Reconnaissance"]} known_false_positives = It's possible for legitimate HTTP requests to be made to URLs containing the suspicious paths. -providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Apache', u'Bro'] +providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Apache", "Bro"] [savedsearch://ESCU - Detect hosts connecting to dynamic domain providers - Rule] type = detection @@ -1532,9 +1532,9 @@ asset_type = Endpoint confidence = medium explanation = The search is querying an accelerated `Network_Resolution` data model to count and list the values of resolved domains for each DNS query and checks that against the list of Dynamic DNS providers (lookup - `dynamic_dns_providers`) by each host (DNS.src) how_to_implement = First, you'll need to ingest data from your DNS operations. This can be done by ingesting logs from your server or data collected passively by Splunk Stream or similar solutions. Specifically, data that contains the domain that is being queried and the IP of the host originating the request must be populating the Network_Resolution data model. This search also leverages a lookup file, dynamic_dns_providers_default.csv, which contains a non-exhaustive list of Dynamic DNS providers. Please consider updating the local lookup periodically by adding new domains to the list of dynamic_dns_providers_local.csv. -annotations = {u'mitre_attack': [u'Exfiltration', u'Exfiltration Over Command and Control Channel', u'Defense Evasion', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 8', u'CIS 12', u'CIS 13'], u'nist': [u'PR.DS', u'PR.PT', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Exfiltration", "Exfiltration Over Command and Control Channel", "Defense Evasion", "Commonly Used Port"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 8", "CIS 12", "CIS 13"], "nist": ["PR.DS", "PR.PT", "DE.AE", "DE.CM"]} known_false_positives = Some users and applications may leverage Dynamic DNS to reach out to some domains on the Internet since dynamic DNS by itself is not malicious, however this activity must be verified. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Detect malicious requests to exploit JBoss servers - Rule] type = detection @@ -1542,9 +1542,9 @@ asset_type = Web Server confidence = high explanation = This search looks for HTTP requests for a URL that has been used to exploit JBoss servers. how_to_implement = You must ingest data from the web server or capture network data that contains web specific information with solutions such as Bro or Splunk Stream, and populating the Web data model -annotations = {u'mitre_attack': [u'Defense Evasion', u'Exploitation of Vulnerability'], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 12', u'CIS 4', u'CIS 18'], u'nist': [u'ID.RA', u'PR.PT', u'PR.IP', u'DE.AE', u'PR.MA', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Exploitation of Vulnerability"], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 12", "CIS 4", "CIS 18"], "nist": ["ID.RA", "PR.PT", "PR.IP", "DE.AE", "PR.MA", "DE.CM"]} known_false_positives = No known false positives for this detection. -providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Apache', u'Bro'] +providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Apache", "Bro"] [savedsearch://ESCU - Detect mshta.exe running scripts in command-line arguments - Rule] type = detection @@ -1552,9 +1552,9 @@ asset_type = Endpoint confidence = medium explanation = Mshta.exe is a built-in Windows utility that can launch HTML files with .hta extensions (HTML applications), javascript, or VBScript. The search detects this behavior by looking for events where the process mshta.exe is executed with command-line arguments that indicate that a script is invoked how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface', u'Persistence'], u'kill_chain_phases': [u'Exploitation'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface", "Persistence"], "kill_chain_phases": ["Exploitation"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Although unlikely, some legitimate applications may exhibit this behavior, triggering a false positive. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect new API calls from user roles - Rule] type = detection @@ -1562,9 +1562,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch will execute first and return the user roles and names of the API calls completed within the last hour, where the type of user identity is AssumedRole. It then appends the historical data to those results in the lookup file. Next, it recalculates the earliest and latest fields for each user role, as well as the name of the API call, and returns only those roles and API calls that have first been seen in the past hour. This is combined with the main search to return the values of API calls, name of the user role, and the earliest and latest time of this activity. It is worth noting that the name of the role of a particular user is parsed as "userName" in the CloudTrail logs. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously seen API call per user roles in CloudTrail" support search once to create a history of previously seen user roles. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = It is possible that there are legitimate user roles making new or infrequently used API calls in your infrastructure, causing the search to trigger. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect new user AWS Console Login - Rule] type = detection @@ -1572,9 +1572,9 @@ asset_type = AWS Instance confidence = medium explanation = In this search, we query CloudTrail logs to look for events that indicate that a user has attempted to log in to the AWS console and group the events using ARN value. Using the previously_seen_users_console_logins.csv lookup file created using the support search, we compare the ARN to all the previously seen users logging into the AWS console. The eval and if functions determine whether the earliest time we see this user ARN was seen within the last hour. The alert will be fired only when a user is seen for first time in the last hour. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Run the "Previously seen users in CloudTrail" support search only once to create a baseline of previously seen IAM users within the last 30 days -annotations = {u'mitre_attack': [u'Credential Access'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 16'], u'nist': [u'DE.DP', u'DE.AE']} +annotations = {"mitre_attack": ["Credential Access"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 16"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = When a legitimate new user logins for the first time, this activity will be detected. Check how old the account is and verify that the user activity is legitimate. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Detect processes used for System Network Configuration Discovery - Rule] type = detection @@ -1582,9 +1582,9 @@ asset_type = Endpoint confidence = high explanation = Attackers have a range of built-in Windows tools they leverage to ascertain the topography of a network from the point of view of a compromised machine. It is uncommon to see these commands execute quickly within short periods of time. This search returns the number of times, as well as the first time and last times, that every process has run for each endpoint. It then executes the macro system_network_configuration_discovery_tools, which looks for processes that are typically used for network configuration discovery. Once you have a list of suspicious process launches for each destination, you can leverage the transaction command to see what processes are fired within a five-minute span on an endpoint and detect only those events where the count of these processes is greater than five. how_to_implement = You must be ingesting data that records registry activity from your hosts to populate the Endpoint data model in the processes node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report reads and writes to the registry or that are populated via Windows event logs, after enabling process tracking in your Windows audit settings. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Installation', u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 2'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Installation", "Command and Control", "Actions on Objectives"], "cis20": ["CIS 2"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = It is uncommon for normal users to execute a series of commands used for network discovery. System administrators often use scripts to execute these commands. These can generate false positives. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Detect web traffic to dynamic domain providers - Rule] type = detection @@ -1592,9 +1592,9 @@ asset_type = Endpoint confidence = high explanation = This search looks for hosts in your environment that may be communicating with a dynamic DNS provider. It checks each URL an endpoint is connecting to against a list of dynamic DNS providers. It returns the source and destination IP address of the web request, the URL requested, and the first time the event occurred. how_to_implement = This search requires you to be ingesting web-traffic logs. You can obtain these logs from indexing data from a web proxy or by using a network-traffic-analysis tool, such as Bro or Splunk Stream. The web data model must contain the URL being requested, the IP address of the host initiating the request, and the destination IP. This search also leverages a lookup file, dynamic_dns_providers_default.csv, which contains a non-exhaustive list of dynamic DNS providers. Consider periodically updating this local lookup file with new domains. -annotations = {u'mitre_attack': [u'Command and Control', u'Web Service', u'Exfiltration Over Command and Control Channel', u'Defense Evasion'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 7', u'CIS 8'], u'nist': [u'PR.IP', u'DE.DP']} +annotations = {"mitre_attack": ["Command and Control", "Web Service", "Exfiltration Over Command and Control Channel", "Defense Evasion"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 7", "CIS 8"], "nist": ["PR.IP", "DE.DP"]} known_false_positives = It is possible that list of dynamic DNS providers is outdated and/or that the URL being requested is legitimate. -providing_technologies = [u'Splunk Stream', u'Bro', u'Bluecoat', u'Palo Alto Firewall'] +providing_technologies = ["Splunk Stream", "Bro", "Bluecoat", "Palo Alto Firewall"] [savedsearch://ESCU - Detection of DNS Tunnels - Rule] type = detection @@ -1602,9 +1602,9 @@ asset_type = Endpoint confidence = low explanation = The search will calculate the distinct count and sum of the length of DNS queries made and DNS answers received by a particular host to alert the analyst if the combined length is greater than 10000, which is not typical behavior. how_to_implement = To successfully implement this search, we must ensure that DNS data is being ingested and mapped to the appropriate fields in the Network_Resolution data model. Fields like src_category are automatically provided by the Assets and Identity Framework shipped with Splunk Enterprise Security. You will need to ensure you are using the Assets and Identity Framework and populating the src_category field. You will also need to enable the `cim_corporate_web_domain_search()` macro which will essentially filter out the DNS queries made to the corporate web domains to reduce alert fatigue. -annotations = {u'mitre_attack': [u'Command and Control', u'Exfiltration', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 13'], u'nist': [u'PR.PT', u'PR.DS']} +annotations = {"mitre_attack": ["Command and Control", "Exfiltration", "Commonly Used Port"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 13"], "nist": ["PR.PT", "PR.DS"]} known_false_positives = It's possible that normal DNS traffic will exhibit this behavior. If an alert is generated, please investigate and validate as appropriate. The threshold can also be modified to better suit your environment. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Detection of tools built by NirSoft - Rule] type = detection @@ -1612,9 +1612,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks for process-creation events accompanied by specific command-line arguments ("scomma" and "stext"). These parameters may be leveraged by a set of free, legitimate tools built by NirSoft. Attackers have been seen abusing the tools' capabilities to steal passwords, set up key loggers, recover account information from mail clients, and conduct other nefarious activities. The search will identify the count, the first and last times a process is executed, the command-line arguments, and the parent process. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Third-party Software', u'Account Discovery'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 3'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Third-party Software", "Account Discovery"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 3"], "nist": ["PR.IP"]} known_false_positives = While legitimate, these NirSoft tools are prone to abuse. You should verfiy that the tool was used for a legitimate purpose. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Disabling Remote User Account Control - Rule] type = detection @@ -1622,9 +1622,9 @@ asset_type = Endpoint confidence = medium explanation = This search checks to see if the registry key SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy was modified. This registry key can be used to disable remote User Account Control. The search returns the count, the first time activity was seen, last time activity was seen, the registry path that was modified, the host where the modification took place and the user that performed the modification. how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report registry modifications. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Modify Registry'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Modify Registry"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = This registry key may be modified via administrators to implement a change in system policy. This type of change should be a very rare occurrence. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - EC2 Instance Modified With Previously Unseen User - Rule] type = detection @@ -1632,9 +1632,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns the ARNs of all successful EC2 instance modifications within the last hour and then appends the historical data in the lookup file to those results. EC2 modification APIs are defined by the macro ec2ModificationAPIs. The search then recalculates the firstTime and lastTime field for each ARN and returns only those ARNs that have first been seen in the past hour. This is combined with the main search to return the time, user, and instance ID of those systems. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen EC2 Launches By User" support search once to create a history of previously seen ARNs. To add or remove APIs that modify an EC2 instance, edit the macro ec2ModificationAPIs. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = It's possible that a new user will start to modify EC2 instances when they haven't before for any number of reasons. Verify with the user that is modifying instances that this is the intended behavior. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - EC2 Instance Started In Previously Unseen Region - Rule] type = detection @@ -1642,9 +1642,9 @@ asset_type = AWS Instance confidence = medium explanation = In this search, we query CloudTrail logs to look for events that indicate that an instance was started in a particular region. Using the previously_seen_aws_regions.csv lookup file created using the support search, we compare the region where this instance was started to all previously observed regions. The eval and if functions determine that the earliest times seen for this region and instance were within the last day. If a new region is detected, it will alert you with "Instance Started in a New Region". However, this region will be added to the list of previously_seen_aws_regions.csv. Please maintain previously_seen_aws_regions.csv how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Run the "Previously seen AWS Regions" support search only once to create of baseline of previously seen regions. -annotations = {u'mitre_attack': [u'Defense Evasion'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 12'], u'nist': [u'DE.DP', u'DE.AE']} +annotations = {"mitre_attack": ["Defense Evasion"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 12"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = It's possible that a user has unknowingly started an instance in a new region. Please verify that this activity is legitimate. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - EC2 Instance Started With Previously Unseen AMI - Rule] type = detection @@ -1652,9 +1652,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns the AMI image ID of all successful EC2 instance launches within the last hour and then appends the historical data from the lookup file to those results. It then recalculates the earliest and latest seen time field for each AMI image ID and returns only those AMI image IDs that have first been seen in the past hour. This is combined with the main search to return the time, user, and instance id of those systems. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen EC2 AMIs" support search once to create a history of previously seen AMIs. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = After a new AMI is created, the first systems created with that AMI will cause this alert to fire. Verify that the AMI being used was created by a legitimate user. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule] type = detection @@ -1662,9 +1662,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns the instance types of all successful EC2 instance launches within the last hour and then appends the historical data in the lookup file to those results. It then recalculates the earliest seen time field for each instance type and returns only those instance types that has first been seen in the past hour. This is combined with the main search to return the time, user, and instance id of those systems. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen EC2 Instance Types" support search once to create a history of previously seen instance types. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = It is possible that an admin will create a new system using a new instance type never used before. Verify with the creator that they intended to create the system with the new instance type. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - EC2 Instance Started With Previously Unseen User - Rule] type = detection @@ -1672,9 +1672,9 @@ asset_type = AWS Instance confidence = medium explanation = The subsearch returns the ARNs of all successful EC2 instance launches within the last hour and then appends the historical data in the lookup file to those results. It then recalculates the firstTime and lastTime field for each ARN and returns only those ARNs that have first been seen in the past hour. This is combined with the main search to return the time, user, and instance id of those systems. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. This search works best when you run the "Previously Seen EC2 Launches By User" support search once to create a history of previously seen ARNs. -annotations = {u'cis20': [u'CIS 1'], u'nist': [u'ID.AM']} +annotations = {"cis20": ["CIS 1"], "nist": ["ID.AM"]} known_false_positives = It's possible that a user will start to create EC2 instances when they haven't before for any number of reasons. Verify with the user that is launching instances that this is the intended behavior. -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Email Attachments With Lots Of Spaces - Rule] type = detection @@ -1682,9 +1682,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at any emails with file attachment names that contain many spaces relative to the length of the file name. Specifically, it checks if spaces make up more than 10% of the number of characters in the file name. This percentage can be tuned for each environment. The search will then output the message ID of the email, the count, the recipient address and the recipient user, first and last time this event was seen and the space ratio of the file attachment name. how_to_implement = You need to ingest data from emails. Specifically, the sender's address and the file names of any attachments must be mapped to the Email data model. The threshold ratio is set to 10%, but this value can be configured to suit each environment. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 7'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 7"], "nist": ["PR.IP"]} known_false_positives = None at this time -providing_technologies = [u'Microsoft Exchange'] +providing_technologies = ["Microsoft Exchange"] [savedsearch://ESCU - Email files written outside of the Outlook directory - Rule] type = detection @@ -1692,9 +1692,9 @@ asset_type = Endpoint confidence = medium explanation = In this search, we are looking for activities consistent with an adversary collecting email data from local machines. The search will detect email files (files with .pst or .ost extensions) created in directories other than the standard Outlook directory (c:\users\username\My Documents\Outlook Files\. how_to_implement = To successfully implement this search, you must be ingesting data that records the file-system activity from your hosts to populate the Endpoint.Filesystem data model node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or by other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. -annotations = {u'mitre_attack': [u'Collection', u'Email Collection'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8']} +annotations = {"mitre_attack": ["Collection", "Email Collection"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"]} known_false_positives = Administrators and users sometimes prefer backing up their email data by moving the email files into a different folder. These attempts will be detected by the search. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Email servers sending high volume traffic to hosts - Rule] type = detection @@ -1702,9 +1702,9 @@ asset_type = Endpoint confidence = medium explanation = This search may look complex, but it's a neat representation of how statistics can help you understand your dataset to bubble up events that are not normal compared to its behavior. The search consists of three parts. The first part of the SPL fetches the data you want to work on. In this search, we calculate the sum of bytes sent and bytes_out from systems categorized as email_server to each host. We then calculate the average and standard deviation for the bytes sent to all the hosts combined and on a per-host basis. Then we set threshold values to deviation_threshold and minimum_data_samples using eval statements. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. We then check for byte transfers that are statistically significantly higher than normal. The search then gives IP address of the host, the time of the increased byte transfer, how much data was transferred, and the average amount of data transfer the email server normally sends to all hosts and to this specific host. Finally, it includes the number of standard deviations away the byte count was from these averages. how_to_implement = This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. -annotations = {u'mitre_attack': [u'Collection', u'Email Collection', u'Commonly Used Port'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 7'], u'nist': [u'PR.PT', u'DE.CM', u'DE.AE']} +annotations = {"mitre_attack": ["Collection", "Email Collection", "Commonly Used Port"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 7"], "nist": ["PR.PT", "DE.CM", "DE.AE"]} known_false_positives = The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers. -providing_technologies = [u'Bro', u'Splunk Stream'] +providing_technologies = ["Bro", "Splunk Stream"] [savedsearch://ESCU - Excessive DNS Failures - Rule] type = detection @@ -1712,9 +1712,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks at DNS traffic with a reply code that is NOT indicative of a successful response. Numerous unsuccessful replies may be indicative of DNS protocol tampering or other malicious activity. If more than 50 of these unsuccessful responses are observed over the time frame of the search, a notable event will be generated. how_to_implement = To successfully implement this search you must ensure that DNS data is populating the Network_Resolution data model. -annotations = {u'mitre_attack': [u'Exfiltration', u'Exfiltration Over Alternative Protocol', u'Command and Control', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 8', u'CIS 9', u'CIS 12'], u'nist': [u'PR.PT', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Exfiltration", "Exfiltration Over Alternative Protocol", "Command and Control", "Commonly Used Port"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 8", "CIS 9", "CIS 12"], "nist": ["PR.PT", "DE.AE", "DE.CM"]} known_false_positives = It is possible legitimate traffic can trigger this rule. Please investigate as appropriate. The threshold for generating an event can also be customized to better suit your environment. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Execution of File With Spaces Before Extension - Rule] type = detection @@ -1722,9 +1722,9 @@ asset_type = Endpoint confidence = medium explanation = This search uses the endpoint data model to look for process names with at least five spaces between the file name and its extension. how_to_implement = To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {u'mitre_attack': [u'Execution', u'Persistence', u'Change Default File Association'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 8'], u'nist': [u'DE.CM', u'PR.PT', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Persistence", "Change Default File Association"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 8"], "nist": ["DE.CM", "PR.PT", "PR.IP"]} known_false_positives = None identified. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Execution of File with Multiple Extensions - Rule] type = detection @@ -1732,9 +1732,9 @@ asset_type = Endpoint confidence = high explanation = This search uses the "Application State" data model to look for process names with specific combinations of double extensions. Relatively straightforward, the search looks for strings in the "process" field that match what you're looking for. how_to_implement = To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. -annotations = {u'mitre_attack': [u'Execution', u'Persistence', u'Change Default File Association'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 8'], u'nist': [u'DE.CM', u'PR.PT', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Persistence", "Change Default File Association"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 8"], "nist": ["DE.CM", "PR.PT", "PR.IP"]} known_false_positives = None identified. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Extended Period Without Successful Netbackup Backups - Rule] type = detection @@ -1742,9 +1742,9 @@ asset_type = Endpoint confidence = high explanation = This search finds all the successful backup messages in your logs, and then looks for the most recent backup time for each system. It then identifies those systems where the most recent successful backup time is over a week ago, and reports on them. how_to_implement = To successfully implement this search you need to first obtain data from your backup solution, either from the backup logs on your hosts, or from a central server responsible for performing the backups. If you do not use Netbackup, you can modify this search for your backup solution. Depending on how often you backup your systems, you may want to modify how far in the past to look for a successful backup, other than the default of seven days. -annotations = {u'cis20': [u'CIS 10'], u'nist': [u'PR.IP']} +annotations = {"cis20": ["CIS 10"], "nist": ["PR.IP"]} known_false_positives = None identified -providing_technologies = [u'Netbackup'] +providing_technologies = ["Netbackup"] [savedsearch://ESCU - File with Samsam Extension - Rule] type = detection @@ -1752,9 +1752,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at file modifications across your hosts and creates notable events when it identifies files with extensions associated with the SamSam ransomware, including `.stubbin`, `.berkshire`, `.satoshi`, `.sophos`, or `.keyxml`. Files with these extensions have been observed in SamSam attacks consisting of payload data or keying material. how_to_implement = You must be ingesting data that records file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Installation'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Installation"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Because these extensions are not typically used in normal operations, you should investigate all results. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - First Time Seen Running Windows Service - Rule] type = detection @@ -1762,9 +1762,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for a change in the status of a Windows service and extracts the name of the service and the action taken by the service. Then the cache file of previously seen Windows services is added to the search. At this point, the search takes two different paths: the first updates the cache file with the latest information and the second searches for services that have never before been seen. It returns the time, the Windows host name, and the service name. how_to_implement = While this search does not require you to adhere to Splunk CIM, you must be ingesting your Windows security-event logs in order for this search to execute successfully. The support search, Previously Seen Running Windows Services, should be run before this search to create the baseline of known Windows services. -annotations = {u'mitre_attack': [u'Execution', u'New Service'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 2', u'CIS 9'], u'nist': [u'ID.AM', u'PR.DS', u'PR.AC', u'DE.AE']} +annotations = {"mitre_attack": ["Execution", "New Service"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 2", "CIS 9"], "nist": ["ID.AM", "PR.DS", "PR.AC", "DE.AE"]} known_false_positives = A previously unseen service is not necessarily malicious. Verify that the service is legitimate and that was installed by a legitimate process. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - First time seen command line argument - Rule] type = detection @@ -1772,9 +1772,9 @@ asset_type = Endpoint confidence = medium explanation = The subsearch returns all events where cmd.exe was used with a /c parameter in the command-line arguments to execute other commands/programs. It appends the historical data to those results in the lookup file. Next, it recalculates the firstTime and lastTime field for command-line execution and outputs this data to the lookup file to update the local cache. It returns only those events that have first been seen in the past one hour. This is combined with the main search to return the time, user, destination, process, parent process, and value of the command-line argument. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must be ingesting logs with both the process name and command line from your endpoints. The complete process name with command-line arguments are mapped to the "process" field in the Endpoint data model. Please make sure you run the support search "Previously seen command line arguments,"—which creates a lookup file called previously_seen_cmd_line_arguments.csv—a historical baseline of all command-line arguments. You must also validate this list. For the search to do accurate calculation, ensure the search scheduling is the same value as the `relative_time` evaluation function. -annotations = {u'mitre_attack': [u'Execution', u'Scripting', u'Persistence', u'Command-Line Interface'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Scripting", "Persistence", "Command-Line Interface"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = Legitimate programs can also use command-line arguments to execute. Please verify the command-line arguments to check what command/program is being executed. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Hiding Files And Directories With Attrib.exe - Rule] type = detection @@ -1782,9 +1782,9 @@ asset_type = confidence = medium explanation = This search is looking to detect command-line execution with of attrib.exe binary with the +h flag set. The +h flag is used to hide a file. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = Some applications and users may legitimately use attrib.exe to interact with the files. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Hosts receiving high volume of network traffic from email server - Rule] type = detection @@ -1792,9 +1792,9 @@ asset_type = Endpoint confidence = medium explanation = This search may look complex, but it's a neat representation of how statistics can help you understand your dataset to bubble up events that are not normal compared to its behavior. The search consists of three parts. The first part of the SPL fetches the data you want to work on. In this search, we calculate the sum of bytes sent and bytes_out from systems categorized as email_server to each host. We then calculate the average and standard deviation for the bytes sent to all the hosts combined and on a per-host basis. Then we set threshold values to deviation_threshold and minimum_data_samples using eval statements. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. We then check for byte transfers that are statistically significantly higher than normal. The search then gives IP address of the host, the time of the increased byte transfer, how much data was transferred, and the average amount of data transfer the email server normally sends to all hosts and to this specific host. Finally, it includes the number of standard deviations away the byte count was from these averages. how_to_implement = This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. -annotations = {u'mitre_attack': [u'Collection', u'Commonly Used Port'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 7'], u'nist': [u'PR.PT', u'DE.CM', u'DE.AE']} +annotations = {"mitre_attack": ["Collection", "Commonly Used Port"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 7"], "nist": ["PR.PT", "DE.CM", "DE.AE"]} known_false_positives = The false-positive rate will vary based on how you set the deviation_threshold and data_samples values. Our recommendation is to adjust these values based on your network traffic to and from your email servers. -providing_technologies = [u'Bro', u'Splunk Stream'] +providing_technologies = ["Bro", "Splunk Stream"] [savedsearch://ESCU - Identify New User Accounts - Rule] type = detection @@ -1802,9 +1802,9 @@ asset_type = Domain Server confidence = medium explanation = Adversaries will often seek to create new user accounts as a means of maintaining access to a target environment. Using this search, we identify accounts created in the last week by comparing the start date in the Identity_Management data model against the current time. how_to_implement = To successfully implement this search, you need to be populating the Enterprise Security Identity_Management data model in the assets and identity framework. -annotations = {u'mitre_attack': [u'Valid Accounts'], u'cis20': [u'CIS 16'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Valid Accounts"], "cis20": ["CIS 16"], "nist": ["PR.IP"]} known_false_positives = If the Identity_Management data model is not updated regularly, this search could give you false positive alerts. Please consider this and investigate appropriately. -providing_technologies = [u'Active Directory'] +providing_technologies = ["Active Directory"] [savedsearch://ESCU - Large Volume of DNS ANY Queries - Rule] type = detection @@ -1812,9 +1812,9 @@ asset_type = DNS Servers confidence = high explanation = This search counts the number of DNS ANY queries received in 5 minutes, and generates a Notable Event if the count exceeds a predefined threshold. The search returns the count, the first time, and the last time a DNS packet was observed with the ANY flag set. how_to_implement = To successfully implement this search you must ensure that DNS data is populating the Network_Resolution data model. -annotations = {u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 11', u'CIS 12'], u'nist': [u'PR.PT', u'DE.AE', u'PR.IP']} +annotations = {"kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 11", "CIS 12"], "nist": ["PR.PT", "DE.AE", "PR.IP"]} known_false_positives = Legitimate ANY requests may trigger this search, however it is unusual to see a large volume of them under typical circumstances. You may modify the threshold in the search to better suit your environment. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule] type = detection @@ -1822,9 +1822,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for PowerShell processes running with specific command-line arguments that indicate that the process will download a file from the Internet without display anything to the user. The search for "*-Exec*" is to check and see if the default execution policy for PowerShell is being overridden on the command-line. The search for "*-WindowStyle*" and "*hidden*" are to see if the window that would normally be displayed will be hidden from the user instead. Finally, the search for "*New-Object*" and "*System.Net.WebClient*" are there to check to see if a PowerShell object that can be used to download files will be created. This search will return the host, the user the process ran under, the process and it's command-line arguments, the number of times it's seen this process, and the first and last times it saw this process. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'PowerShell', u'Scripting'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 7', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "PowerShell", "Scripting"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = Legitimate process can have this combination of command-line options, but it's not common. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Malicious PowerShell Process - Encoded Command - Rule] type = detection @@ -1832,9 +1832,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for PowerShell processes that are passing encoded commands on the command-line. The flags "-EncodedCommand" and "-enc" are two different possible flags that can be used to pass base64 encoded commands to PowerShell. This search will return the host, the user the process ran under, the process and it's command-line arguments, the number of times it's seen this process, and the first and last times it saw this process. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'PowerShell', u'Scripting'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 7', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "PowerShell", "Scripting"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = System administrators may use this option, but it's not common. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule] type = detection @@ -1842,9 +1842,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for PowerShell processes that were launched using a parameter designed to bypass the local PowerShell execution policy. By default, the policy is set to "Restricted," which disables the execution of PowerShell scripts. In environments that make heavy use of PowerShell, the policy can be set to allow only scripts signed by a trusted publisher. Malicious PowerShell use almost always includes the parameter -ExecutionPolicy bypass. PowerShell is very liberal when it comes to interpreting command-line parameters passed to it. For example, the parameter we look for, -ExecutionPolicy, can be abbreviated to -Execution, -Exec, or even -ex. As such, we look for * -ex*, which should catch all variations of this parameter, followed by the keyword bypass. This search will return the host, the user the process ran under, the process and its command-line arguments, the number of times it has seen this process, and the first and last times it saw this process. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'PowerShell', u'Scripting'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 7', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "PowerShell", "Scripting"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = There may be legitimate reasons to bypass the PowerShell execution policy. The PowerShell script being run with this parameter should be validated to ensure that it is legitimate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule] type = detection @@ -1852,9 +1852,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for PowerShell processes that have a number of suspicious flags on the command-line. It is looking for flags are passing encoded commands on the command-line. The flags -EncodedCommand and -enc are two different possible flags that can be used to pass base64 encoded commands to PowerShell. The *-Exec* flag looks to see it the default execution policy of PowerShell is being overridden, while the *-NonI* flag tells the PowerShell process that this will be a noninteractive process, so the user doesn't know about the process. This search will return the host, the user the process ran under, the process and it's command-line arguments, the number of times it's seen this process, and the first and last times it saw this process. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'PowerShell', u'Scripting'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 7', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "PowerShell", "Scripting"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = Legitimate process can have this combination of command-line options, but it's not common. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule] type = detection @@ -1862,9 +1862,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for PowerShell processes that are passing command-line arguments with unusual characters (backticks and carets) that are PowerShell specific escape characters. Attackers use this obfuscation technique since it does not affect the functionality of PowerShell and it will bypass standard security controls that look for straight up malicious strings and commands. The search counts the occurrence of these obfuscation characters and lists out destination IPs running these PowerShell commands. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'PowerShell', u'Scripting'], u'kill_chain_phases': [u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 7', u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "PowerShell", "Scripting"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "cis20": ["CIS 3", "CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = These characters might be legitimately on the command-line, but it is not common. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Monitor DNS For Brand Abuse - Rule] type = detection @@ -1872,9 +1872,9 @@ asset_type = Endpoint confidence = high explanation = This search gathers all the answers to each system's DNS query, then filters out all queries that do not appear on the list of faux "look-a-like" domains that have been generated from the brand abuse domains you are monitoring. how_to_implement = You need to ingest data from your DNS logs. Specifically you must ingest the domain that is being queried and the IP of the host originating the request. Ideally, you should also be ingesting the answer to the query and the query type. This approach allows you to also create your own localized passive DNS capability which can aid you in future investigations. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. -annotations = {u'kill_chain_phases': [u'Delivery', u'Actions on Objectives']} +annotations = {"kill_chain_phases": ["Delivery", "Actions on Objectives"]} known_false_positives = None at this time -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Monitor Email For Brand Abuse - Rule] type = detection @@ -1882,9 +1882,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at the sender address in email headers, and identifies those with a sender address using a domain name that matches the list of permutations generated for the domain you want to monitor. how_to_implement = You need to ingest email header data. Specifically the sender's address (src_user) must be populated. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. -annotations = {u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 7'], u'nist': [u'PR.IP']} +annotations = {"kill_chain_phases": ["Delivery"], "cis20": ["CIS 7"], "nist": ["PR.IP"]} known_false_positives = None at this time -providing_technologies = [u'Microsoft Exchange', u'Bro', u'Splunk Stream'] +providing_technologies = ["Microsoft Exchange", "Bro", "Splunk Stream"] [savedsearch://ESCU - Monitor Registry Keys for Print Monitors - Rule] type = detection @@ -1892,9 +1892,9 @@ asset_type = Endpoint confidence = medium explanation = In this search, we look for modifications to registry keys used for adding print-monitor entries on Microsoft platforms via the registry_path field in the endpoint data model. It then provides the destination, command used to initiate the change, the user who conducted this activity, the resource affected (registry_key_name), and the entire path of the registry. how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report registry modifications. -annotations = {u'mitre_attack': [u'Persistence', u'Privilege Escalation', u'Local Port Monitor'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8', u'CIS 5'], u'nist': [u'PR.PT', u'DE.CM', u'PR.AC']} +annotations = {"mitre_attack": ["Persistence", "Privilege Escalation", "Local Port Monitor"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8", "CIS 5"], "nist": ["PR.PT", "DE.CM", "PR.AC"]} known_false_positives = You will encounter noise from legitimate print-monitor registry entries. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Monitor Web Traffic For Brand Abuse - Rule] type = detection @@ -1902,9 +1902,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at all the URLs an endpoint is connecting to and then checks the URL against a list of faux domains that could be indicative of brand abuse. how_to_implement = You need to ingest data from your web traffic. This can be accomplished by indexing data from a web proxy, or using a network traffic analysis tool, such as Bro or Splunk Stream. You also need to have run the search "ESCU - DNSTwist Domain Names", which creates the permutations of the domain that will be checked for. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 7'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 7"], "nist": ["PR.IP"]} known_false_positives = None at this time -providing_technologies = [u'Splunk Stream', u'Bro', u'Bluecoat', u'Palo Alto Firewall'] +providing_technologies = ["Splunk Stream", "Bro", "Bluecoat", "Palo Alto Firewall"] [savedsearch://ESCU - No Windows Updates in a time frame - Rule] type = detection @@ -1912,9 +1912,9 @@ asset_type = Endpoint confidence = medium explanation = Keeping your systems up-to-date with the latest patches is an important step in keeping your systems secured. For Windows endpoints, Microsoft typically releases patches on the second Tuesday of every month. These patches contain fixes for vulnerabilities in the system that could potentially be exploited by malicious actors. This search checks for messages regarding Windows updates in the 'Update' data model. If a message indicating a successful update has not been observed in 60 days, a notable event will be generated. These systems should be checked to determine why it has not been updated in that time frame. how_to_implement = To successfully implement this search, it requires that the 'Update' data model is being populated. This can be accomplished by ingesting Windows events or the Windows Update log via a universal forwarder on the Windows endpoints you wish to monitor. The Windows add-on should be also be installed and configured to properly parse Windows events in Splunk. There may be other data sources which can populate this data model, including vulnerability management systems. -annotations = {u'cis20': [u'CIS 18'], u'nist': [u'PR.PT', u'PR.MA']} +annotations = {"cis20": ["CIS 18"], "nist": ["PR.PT", "PR.MA"]} known_false_positives = None identified -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Open Redirect in Splunk Web - Rule] type = detection @@ -1922,9 +1922,9 @@ asset_type = Splunk Server confidence = medium explanation = This search looks within Splunk's internal logs for evidence of CVE-2016-4859 open redirect exploitation attempts. how_to_implement = No extra steps needed to implement this search. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Exploitation of Vulnerability'], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 3', u'CIS 4', u'CIS 18'], u'nist': [u'ID.RA', u'RS.MI', u'PR.PT', u'PR.AC', u'PR.IP', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Exploitation of Vulnerability"], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 3", "CIS 4", "CIS 18"], "nist": ["ID.RA", "RS.MI", "PR.PT", "PR.AC", "PR.IP", "DE.CM"]} known_false_positives = None identified -providing_technologies = [u'Splunk Enterprise'] +providing_technologies = ["Splunk Enterprise"] [savedsearch://ESCU - Osquery pack - ColdRoot detection - Rule] type = detection @@ -1932,9 +1932,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks at the Alerts data model to identify those generated from the osquery osx-attacks.conf pack, which search for the ColdRoot RAT. how_to_implement = In order to properly run this search, Splunk needs to ingest data from your osquery deployed agents with the [osx-attacks.conf](https://github.com/facebook/osquery/blob/experimental/packs/osx-attacks.conf#L599) pack enabled. Also the [TA-OSquery](https://github.com/d1vious/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the osquery data populate the Alerts data model -annotations = {u'mitre_attack': [u'Execution', u'Persistence', u'Command and Control'], u'kill_chain_phases': [u'Installation', u'Command and Control'], u'cis20': [u'CIS 4', u'CIS 8'], u'nist': [u'DE.DP', u'DE.CM', u'PR.PT']} +annotations = {"mitre_attack": ["Execution", "Persistence", "Command and Control"], "kill_chain_phases": ["Installation", "Command and Control"], "cis20": ["CIS 4", "CIS 8"], "nist": ["DE.DP", "DE.CM", "PR.PT"]} known_false_positives = There are no known false positives. -providing_technologies = [u'OSquery'] +providing_technologies = ["OSquery"] [savedsearch://ESCU - Overwriting Accessibility Binaries - Rule] type = detection @@ -1942,9 +1942,9 @@ asset_type = Endpoint confidence = high explanation = This search returns all the different accessibility binaries that have been modified for each Windows host. how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. -annotations = {u'mitre_attack': [u'Persistence', u'Accessibility Features'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Persistence", "Accessibility Features"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Microsoft may provide updates to these binaries. Verify that these changes do not correspond with your normal software update cycle. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Process Execution via WMI - Rule] type = detection @@ -1952,9 +1952,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers are increasingly abusing Windows Management Infrastructure (WMI) for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for processes launched via WMI, either remotely or locally, by looking for processes launched by WmiPrvSE.exe, which is the process WMI uses to execute new processes and commands. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Although unlikely, administrators may use wmi to execute commands for legitimate purposes. -providing_technologies = [u'Carbon Black Response', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Processes Tapping Keyboard Events - Rule] type = detection @@ -1962,9 +1962,9 @@ asset_type = Endpoint confidence = medium explanation = The search leverages Alerts generated from the osquery osx-attacks.conf pack search `Keyboard_Event_Taps` to detect when a process is monitoring the keystrokes of a machine, This is a common technique used by macOS remote access trojans to log keystrokes from a machine how_to_implement = In order to properly run this search, Splunk needs to ingest data from your osquery deployed agents with the [osx-attacks.conf](https://github.com/facebook/osquery/blob/experimental/packs/osx-attacks.conf#L599) pack enabled. Also the [TA-OSquery](https://github.com/d1vious/TA-osquery) must be deployed across your indexers and universal forwarders in order to have the osquery data populate the Alerts data model. -annotations = {u'mitre_attack': [u'Collection'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 4', u'CIS 8'], u'nist': [u'DE.DP']} +annotations = {"mitre_attack": ["Collection"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 4", "CIS 8"], "nist": ["DE.DP"]} known_false_positives = There might be some false positives as keyboard event taps are used by processes like Siri and Zoom video chat, for some good examples of processes to exclude please see [this](https://github.com/facebook/osquery/pull/5345#issuecomment-454639161) comment. -providing_technologies = [u'OSquery'] +providing_technologies = ["OSquery"] [savedsearch://ESCU - Processes created by netsh - Rule] type = detection @@ -1972,9 +1972,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for all processes with the parent process "c:\Windows\System32\netsh.exe" and returns the process, the command line used to execute it, the host name, and the user context under which it ran. how_to_implement = To successfully implement this search, you must be ingesting logs with the process name, command-line arguments, and parent processes from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface", "Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = It is unusual for netsh.exe to have any child processes in most environments. It makes sense to investigate the child process and verify whether the process spawned is legitimate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Processes launching netsh - Rule] type = detection @@ -1982,9 +1982,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for all the parent processes of netsh.exe and returns that process, the command-line used to execute it, the host name, and the user context under which it ran. how_to_implement = To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model -annotations = {u'mitre_attack': [u'Execution', u'Command-Line Interface', u'Persistence', u'Defense Evasion', u'Disabling Security Tools'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Command-Line Interface", "Persistence", "Defense Evasion", "Disabling Security Tools"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Some VPN applications are known to launch netsh.exe. Outside of these instances, it is unusual for an executable to launch netsh.exe and run commands. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Prohibited Network Traffic Allowed - Rule] type = detection @@ -1992,9 +1992,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks for traffic marked 'is_prohibited' in the Enterprise Security lookup table 'interesting_ports_lookup', and then determines if any network devices have an associated 'allow' action on that traffic by checking the Network_Traffic data model. how_to_implement = In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search requires the Network_Traffic data model be populated. -annotations = {u'mitre_attack': [u'Command and Control', u'Commonly Used Port', u'Exfiltration', u'Exfiltration Over Alternative Protocol'], u'kill_chain_phases': [u'Delivery', u'Command and Control'], u'cis20': [u'CIS 9', u'CIS 12'], u'nist': [u'DE.AE', u'PR.AC']} +annotations = {"mitre_attack": ["Command and Control", "Commonly Used Port", "Exfiltration", "Exfiltration Over Alternative Protocol"], "kill_chain_phases": ["Delivery", "Command and Control"], "cis20": ["CIS 9", "CIS 12"], "nist": ["DE.AE", "PR.AC"]} known_false_positives = None identified -providing_technologies = [u'Palo Alto Firewall', u'Bro', u'Splunk Stream'] +providing_technologies = ["Palo Alto Firewall", "Bro", "Splunk Stream"] [savedsearch://ESCU - Prohibited Software On Endpoint - Rule] type = detection @@ -2002,9 +2002,9 @@ asset_type = Endpoint confidence = high explanation = This search returns the number of times, as well as the first and last time, every process has run for each endpoint and user. It then displays only those processes that you have marked as "prohibited" in the Enterprise Security "Interesting Processes" table. how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the processes node. This is typically populated via endpoint detection-and-response products, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is usually generated via logs that report reads and writes to the registry or populated via Windows event logs, after enabling process tracking in your Windows audit settings. In addition, you must also have processes marked as "prohibited" in the Enterprise Security interesting processes table. To include the processes marked as "prohibited", which is included with ES Content Updates, run the included search Support - Add Prohibited Processes to ES. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Installation', u'Command and Control', u'Actions on Objectives'], u'cis20': [u'CIS 2'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Installation", "Command and Control", "Actions on Objectives"], "cis20": ["CIS 2"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = None identified -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Protocol or Port Mismatch - Rule] type = detection @@ -2012,9 +2012,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for instances in which the protocol observed is not consistent with the port and transport protocol typically used for that protocol. For example, looking for network traffic other than HTTP running over TCP port 80. Such behavior could indicate a misconfiguration or a custom command and control protocol that has been designed to look like ordinary web traffic. The search will also identify if HTTP traffic is observed running on unexpected ports. This can be common in many environments. how_to_implement = Running this search properly requires a technology that can inspect network traffic and identify common protocols. Technologies such as Bro and Palo Alto Networks firewalls are two examples that will identify protocols via inspection, and not just assume a specific protocol based on the transport protocol and ports. -annotations = {u'mitre_attack': [u'Command and Control', u'Commonly Used Port'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 9', u'CIS 12'], u'nist': [u'DE.AE', u'PR.AC']} +annotations = {"mitre_attack": ["Command and Control", "Commonly Used Port"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 9", "CIS 12"], "nist": ["DE.AE", "PR.AC"]} known_false_positives = None identified -providing_technologies = [u'Palo Alto Firewall', u'Bro', u'Splunk Stream'] +providing_technologies = ["Palo Alto Firewall", "Bro", "Splunk Stream"] [savedsearch://ESCU - Protocols passing authentication in cleartext - Rule] type = detection @@ -2022,9 +2022,9 @@ asset_type = Endpoint confidence = medium explanation = This search is checking for traffic on well-known ports that are associated with protocols that pass authentication in cleartext. how_to_implement = This search requires you to be ingesting your network traffic, and populating the Network_Traffic data model. -annotations = {u'mitre_attack': [u'Credential Access', u'Lateral Movement', u'Collection'], u'kill_chain_phases': [u'Reconnaissance', u'Actions on Objectives'], u'cis20': [u'CIS 9', u'CIS 14'], u'nist': [u'PR.PT', u'DE.AE', u'PR.AC', u'PR.DS']} +annotations = {"mitre_attack": ["Credential Access", "Lateral Movement", "Collection"], "kill_chain_phases": ["Reconnaissance", "Actions on Objectives"], "cis20": ["CIS 9", "CIS 14"], "nist": ["PR.PT", "DE.AE", "PR.AC", "PR.DS"]} known_false_positives = Some networks may use kerberized FTP or telnet servers, however, this is rare. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Reg.exe Manipulating Windows Services Registry Keys - Rule] type = detection @@ -2032,9 +2032,9 @@ asset_type = Endpoint confidence = high explanation = This search looks for modifications to registry paths that specify the definition and configuration of Windows services by reg.exe. Reg.exe is a Windows utility that allows for manipulation of the registry via the command line. Malware often uses the Windows services architecture to persist, hide in plain sight, and gain the ability to interact with the Windows kernel. While it is common to modify the configuration of Windows services (and new services may be created with software installs), the use of reg.exe to create or modify a service configuration is unusual and a technique commonly used by attackers. The search returns the count, the first time the activity was seen, the last time activity was seen, the registry path that was modified, the host where the modification took place, and the user that performed the modification. how_to_implement = To successfully implement this search you need to be ingesting information on registry changes that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` nodes. -annotations = {u'mitre_attack': [u'Persistence', u'Privilege Escalation', u'New Service', u'Modify Existing Service', u'Defense Evasion', u'Disabling Security Tools'], u'kill_chain_phases': [u'Installation'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 8'], u'nist': [u'PR.IP', u'PR.PT', u'PR.AC', u'PR.AT', u'DE.CM']} +annotations = {"mitre_attack": ["Persistence", "Privilege Escalation", "New Service", "Modify Existing Service", "Defense Evasion", "Disabling Security Tools"], "kill_chain_phases": ["Installation"], "cis20": ["CIS 3", "CIS 5", "CIS 8"], "nist": ["PR.IP", "PR.PT", "PR.AC", "PR.AT", "DE.CM"]} known_false_positives = It is unusual for a service to be created or modified by directly manipulating the registry. However, there may be legitimate instances of this behavior. It is important to validate and investigate, as appropriate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Reg.exe used to hide files/directories via registry keys - Rule] type = detection @@ -2042,9 +2042,9 @@ asset_type = confidence = medium explanation = Reg.exe is a binary native to Windows platform used to edit the registry hives of the system. Attackers can leverage this binary to hide files by passing in arguments that are used to hide the files. In the search, we first gather results with keywords, add, Hidden, and REG_DWORD, that will be in the raw event and filter by process and the command-line. We then leverage regular expressions on the command-line field to look for /d value as 2 which is responsible for hiding a file or directory. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Persistence'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Persistence"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = None at the moment -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Registry Keys Used For Persistence - Rule] type = detection @@ -2052,9 +2052,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for specific registry paths that malware often uses to ensure survivability and persistence on system startup. The search returns the count, the first time the activity was seen, the last time the activity was seen, the registry path that was modified, the host where the modification took place and the user that performed the modification. how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response products, such as Carbon Black or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -annotations = {u'mitre_attack': [u'Persistence', u'Registry Run Keys / Start Folder', u'AppInit DLLs', u'Authentication Package'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM', u'DE.AE']} +annotations = {"mitre_attack": ["Persistence", "Registry Run Keys / Start Folder", "AppInit DLLs", "Authentication Package"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM", "DE.AE"]} known_false_positives = There are many legitimate applications that must execute on system startup and will use these registry keys to accomplish that task. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Registry Keys Used For Privilege Escalation - Rule] type = detection @@ -2062,9 +2062,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for specific registry paths that malware often uses to elevate privileges. The search returns the count, the first time the activity was seen, the last time the activity was seen, the registry path that was modified, the host where the modification took place, and the user who performed the modification. how_to_implement = To successfully implement this search, you must be ingesting data that records registry activity from your hosts to populate the endpoint data model in the registry node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -annotations = {u'mitre_attack': [u'Privilege Escalation', u'Persistence', u'Accessibility Features'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Privilege Escalation", "Persistence", "Accessibility Features"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = There are many legitimate applications that must execute upon system startup and will use these registry keys to accomplish that task. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Registry Keys for Creating SHIM Databases - Rule] type = detection @@ -2072,9 +2072,9 @@ asset_type = Endpoint confidence = medium explanation = In this search, we look for modifications to registry keys used for shim databases on Microsoft platforms via the object_category and object_path field in the Change_Analysis data model and give you the destination, command used to initiate the change, the user who conducted this activity, the resource affected(object), and the whole path of the object. An application compatibility shim is a small library that transparently intercepts an API (via hooking), changes the parameters passed, handles the operation itself, or redirects the operation elsewhere, such as additional code stored on a system. This capability can be also leveraged by attackers to create and store malicious files in a shim database as observed in CARBANAK backdoor. how_to_implement = To successfully implement this search, you must populate the Change_Analysis data model. This is typically populated via endpoint detection and response products, such as Carbon Black or other endpoint data sources such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -annotations = {u'mitre_attack': [u'Persistence', u'Application Shimming'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Persistence", "Application Shimming"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = There are many legitimate applications that leverage shim databases for compatibility purposes for legacy applications -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Remote Desktop Network Bruteforce - Rule] type = detection @@ -2082,9 +2082,9 @@ asset_type = Endpoint confidence = medium explanation = This search monitors for abnormal amounts of remote-desktop (RDP) traffic from a source to a destination that may be indicative of a brute-force attack. It does this by filtering out RDP traffic from the Network_Traffic.All_Traffic data model, using twice the standard deviation of all source-to-destination connections. If any tuple is within more than two standard deviations of all other usual RDP traffic flows, it is indicative of a brute-force attack. how_to_implement = You must ensure that your network traffic data is populating the Network_Traffic data model. -annotations = {u'mitre_attack': [u'Credential Access', u'Remote Desktop Protocol', u'Lateral Movement'], u'kill_chain_phases': [u'Reconnaissance', u'Delivery'], u'cis20': [u'CIS 12', u'CIS 9', u'CIS 16'], u'nist': [u'DE.AE', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Credential Access", "Remote Desktop Protocol", "Lateral Movement"], "kill_chain_phases": ["Reconnaissance", "Delivery"], "cis20": ["CIS 12", "CIS 9", "CIS 16"], "nist": ["DE.AE", "PR.AC", "PR.IP"]} known_false_positives = RDP gateways may have unusually high amounts of traffic from all other hosts' RDP applications in the network. -providing_technologies = [u'Bro', u'Splunk Stream'] +providing_technologies = ["Bro", "Splunk Stream"] [savedsearch://ESCU - Remote Desktop Network Traffic - Rule] type = detection @@ -2092,9 +2092,9 @@ asset_type = Endpoint confidence = medium explanation = This search finds systems that do not commonly communicate use remote desktop. It does this by filtering out all systems that have the "common_rdp_source" or "common_rdp_destination" category applied to that system. Categories are applied to systems using the Assets and Identity framework. how_to_implement = To successfully implement this search you need to identify systems that commonly originate remote desktop traffic and that commonly receive remote desktop traffic. You can use the included support search "Identify Systems Creating Remote Desktop Traffic" to identify systems that originate the traffic and the search "Identify Systems Receiving Remote Desktop Traffic" to identify systems that receive a lot of remote desktop traffic. After identifying these systems, you will need to add the "common_rdp_source" or "common_rdp_destination" category to that system depending on the usage, using the Enterprise Security Assets and Identities framework. This can be done by adding an entry in the assets.csv file located in SA-IdentityManagement/lookups. -annotations = {u'mitre_attack': [u'Lateral Movement', u'Remote Desktop Protocol', u'Commonly Used Port'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 9', u'CIS 16'], u'nist': [u'DE.AE', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Lateral Movement", "Remote Desktop Protocol", "Commonly Used Port"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 9", "CIS 16"], "nist": ["DE.AE", "PR.AC", "PR.IP"]} known_false_positives = Remote Desktop may be used legitimately by users on the network. -providing_technologies = [u'Bro', u'Splunk Stream'] +providing_technologies = ["Bro", "Splunk Stream"] [savedsearch://ESCU - Remote Desktop Process Running On System - Rule] type = detection @@ -2102,9 +2102,9 @@ asset_type = Endpoint confidence = medium explanation = This search finds systems that do not commonly use remote desktop, but which begin using it. It filters out all systems that have the "common_rdp_source" category applied. Categories are applied to systems using the Assets and Identity framework. how_to_implement = To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. The search requires you to identify systems that do not commonly use remote desktop. You can use the included support search "Identify Systems Using Remote Desktop" to identify these systems. After identifying them, you will need to add the "common_rdp_source" category to that system using the Enterprise Security Assets and Identities framework. This can be done by adding an entry in the assets.csv file located in SA-IdentityManagement/lookups. -annotations = {u'mitre_attack': [u'Lateral Movement', u'Remote Desktop Protocol'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 9', u'CIS 16'], u'nist': [u'DE.AE', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Lateral Movement", "Remote Desktop Protocol"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 9", "CIS 16"], "nist": ["DE.AE", "PR.AC", "PR.IP"]} known_false_positives = Remote Desktop may be used legitimately by users on the network. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Remote Process Instantiation via WMI - Rule] type = detection @@ -2112,9 +2112,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers are increasingly abusing native Windows utilities such as wmic.exe as a means to "live off the land", and avoid introducing new executables to the target system. In this search, we are looking for instances of wmic.exe being run with various parameters that are not typically used by administrators. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = The wmic.exe utility is a benign Windows application. It may be used legitimately by Administrators with these parameters for remote system administration, but it's relatively uncommon. -providing_technologies = [u'Carbon Black Response', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Remote Registry Key modifications - Rule] type = detection @@ -2122,9 +2122,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for modifications made to the Windows registry from remote locations using reg.exe—a tool used to create/update/delete/modify Windows registry keys. It is accomplished through specifying the machine names in the registry path, by entering double backslashes, followed by a computer name. In this search, we look for registry changes where the registry path contains the name of a remote computer. The search returns the number of times the remote server has been accessed, the first and last times the activity occurred, the name of the modified registry path, the host on which the modification took place, and the name of the user that performed the modification. how_to_implement = To successfully implement this search, you must populate the Change_Analysis data model. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the registry. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Persistence', u'Lateral Movement'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Persistence", "Lateral Movement"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = This technique may be legitimately used by administrators to modify remote registries, so it's important to filter these events out. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Remote WMI Command Attempt - Rule] type = detection @@ -2132,9 +2132,9 @@ asset_type = Endpoint confidence = medium explanation = Many a times, attackers leverage native Windows utilities that are designed to help administrators better manage their systems, infrastructure, and auditing, but are instead leveraged for malicious purposes. In this case, we are looking for instances of wmic.exe being run with various parameters that are not typically used by administrators. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Administrators may use this legitimately to gather info from remote systems. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - RunDLL Loading DLL By Ordinal - Rule] type = detection @@ -2142,9 +2142,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for rundll32.exe being run, loading a DLL out of a directory or subdirectory of AppData, and specifying the function at ordinal 2 be run. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Rundll32'], u'kill_chain_phases': [u'Installation'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution", "Rundll32"], "kill_chain_phases": ["Installation"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = While not common, loading a DLL under %AppData% and calling a function by ordinal is possible by a legitimate process -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - SMB Traffic Spike - Rule] type = detection @@ -2152,9 +2152,9 @@ asset_type = Endpoint confidence = medium explanation = Server Message Block (SMB) traffic, a protocol used for Windows file sharing-activity, is often leveraged by attackers. One example of SMB abuse was the WannaCry ransomware, which leveraged a vulnerability in the SMB protocol to propagate to other systems. Attackers have also used SMB for lateral movement with a target environment and to test credentials against target systems. While SMB is highly prevalent in Windows environments, a spike in SMB traffic may still be indicative of this type of malicious activity. This search looks for a traffic spike in SMB traffic from a particular system. If such a spike is detected, you may want to investigate the source and analyze the cause of the abnormal traffic. how_to_implement = This search requires you to be ingesting your network traffic logs and populating the Network_Traffic data model. -annotations = {u'mitre_attack': [u'Commonly Used Port'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Commonly Used Port"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = A file server may experience high-demand loads that could cause this analytic to trigger. -providing_technologies = [u'Bro', u'Splunk Stream'] +providing_technologies = ["Bro", "Splunk Stream"] [savedsearch://ESCU - SQL Injection with Long URLs - Rule] type = detection @@ -2162,9 +2162,9 @@ asset_type = Database Server confidence = medium explanation = This search looks only at your web servers and returns the source, the web server, the URL and its length, and the user agent associated with HTTP GET requests for extremely long URLs or user agent lengths with more than three common SQL commands found within the URL. how_to_implement = To successfully implement this search, you need to be monitoring network communications to your web servers or ingesting your HTTP logs and populating the Web data model. You must also identify your web servers in the Enterprise Security assets table. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Exploitation of Vulnerability', u'Execution', u'Commonly Used Port'], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 4', u'CIS 13', u'CIS 18'], u'nist': [u'PR.DS', u'ID.RA', u'PR.PT', u'PR.IP', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Exploitation of Vulnerability", "Execution", "Commonly Used Port"], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 4", "CIS 13", "CIS 18"], "nist": ["PR.DS", "ID.RA", "PR.PT", "PR.IP", "DE.CM"]} known_false_positives = It's possible that legitimate traffic will have long URLs or long user agent strings and that common SQL commands may be found within the URL. Please investigate as appropriate. -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Samsam Test File Write - Rule] type = detection @@ -2172,9 +2172,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at file modifications across your hosts and monitors for a file named "test.txt" written to "windows\system32". This file is copied to potential targets during SamSam ransomware attacks to test the attacker's ability to access remote systems. If the file is successfully copied to the system, the system is added to a list of targets on which to deploy ransomware. how_to_implement = You must be ingesting data that records the file-system activity from your hosts to populate the Endpoint file-system data-model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = No false positives have been identified. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Sc.exe Manipulating Windows Services - Rule] type = detection @@ -2182,9 +2182,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for the execution of sc.exe with parameters that indicate the utility is being used to create a new Windows service, or modify an existing one. Attackers often create a new service to host their malicious code, or they may take a non-critical service or one that is disabled, and modify it to point to their malware and enable the service if necessary. It is unusual for a service to be created or modified using the sc.exe utility. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Persistence', u'Privilege Escalation', u'New Service', u'Modify Existing Service', u'Defense Evasion', u'Disabling Security Tools'], u'kill_chain_phases': [u'Installation'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 8'], u'nist': [u'PR.IP', u'PR.PT', u'PR.AC', u'PR.AT', u'DE.CM']} +annotations = {"mitre_attack": ["Persistence", "Privilege Escalation", "New Service", "Modify Existing Service", "Defense Evasion", "Disabling Security Tools"], "kill_chain_phases": ["Installation"], "cis20": ["CIS 3", "CIS 5", "CIS 8"], "nist": ["PR.IP", "PR.PT", "PR.AC", "PR.AT", "DE.CM"]} known_false_positives = Using sc.exe to manipulate Windows services is uncommon. However, there may be legitimate instances of this behavior. It is important to validate and investigate as appropriate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Scheduled Task Name Used by Dragonfly Threat Actors - Rule] type = detection @@ -2192,9 +2192,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks for execution of schtasks.exe with parameters that indicate that a specific task "reset," whose name is associated with the Dragonfly threat actor--has been created or deleted. Schtasks.exe is a native Windows program that is used to schedule tasks on local or remote systems. Attackers often leverage this capability to schedule the execution of commands or establish persistence. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Scheduled Task'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Scheduled Task"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3"], "nist": ["PR.IP"]} known_false_positives = No known false positives -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Scheduled tasks used in BadRabbit ransomware - Rule] type = detection @@ -2202,9 +2202,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks for execution of schtasks.exe with parameters that indicate that specific task names related to the Bad Rabbit ransomware were created or deleted. The specific task name used are rhaegal, drogon and viserion_. Schtasks.exe is a native windows program that is used to schedule tasks on local or remote systems. Attackers often leverage this capability to schedule the execution of commands or establish persistence. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Persistence', u'Lateral Movement', u'Execution', u'Scheduled Task'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Persistence", "Lateral Movement", "Execution", "Scheduled Task"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3"], "nist": ["PR.IP"]} known_false_positives = No known false positives -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Schtasks scheduling job on remote system - Rule] type = detection @@ -2212,9 +2212,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks for execution of schtasks.exe with parameters that indicate a task is being scheduled on a remote host. Schtasks.exe is a native windows program that is used to schedule tasks on local or remote systems. Attackers often leverage this capability to schedule the execution of commands or malicious executables on remote systems. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Persistence', u'Lateral Movement', u'Execution', u'Scheduled Task', u'Remote Services'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Persistence", "Lateral Movement", "Execution", "Scheduled Task", "Remote Services"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3"], "nist": ["PR.IP"]} known_false_positives = Administrators may create jobs on remote systems, but this activity is usually limited to a small set of hosts or users. It is important to validate and investigate as appropriate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Schtasks used for forcing a reboot - Rule] type = detection @@ -2222,9 +2222,9 @@ asset_type = Endpoint confidence = medium explanation = The search looks for execution of schtasks.exe with parameters that indicate a task is being scheduled that would cause a forced reboot on the host. Schtasks.exe is a native windows program that is used to schedule tasks on local or remote systems. Attackers often leverage this capability to schedule the execution of commands or establish persistence. This tactic is leveraged by the Bad Rabbit Ransomware. how_to_implement = To successfully implement this search you need to be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {u'mitre_attack': [u'Persistence', u'Execution', u'Scheduled Task'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Persistence", "Execution", "Scheduled Task"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3"], "nist": ["PR.IP"]} known_false_positives = Administrators may create jobs on systems forcing reboots to perform updates, maintenance, etc. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Script Execution via WMI - Rule] type = detection @@ -2232,9 +2232,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers are increasingly abusing Windows Management Infrastructure for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for scripts launched via WMI, either remotely or locally, by looking for the execution of scrcons.exe, which is the scripting host used by WMI, similar to wscript or cscript. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Although unlikely, administrators may use wmi to launch scripts for legitimate purposes. -providing_technologies = [u'Carbon Black Response', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Shim Database File Creation - Rule] type = detection @@ -2242,9 +2242,9 @@ asset_type = Endpoint confidence = high explanation = This search looks for files being created in Windows\AppPatch\Custom and Windows\AppPatch\Custom64, the location where shim databases are installed. It will return all the files created, as well as the time of creation for the first and last file for each endpoint. how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. -annotations = {u'mitre_attack': [u'Persistence', u'Application Shimming'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Persistence", "Application Shimming"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = Because legitimate shim files are created and used all the time, this event, in itself, is not suspicious. However, if there are other correlating events, it may warrant further investigation. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Shim Database Installation With Suspicious Parameters - Rule] type = detection @@ -2252,9 +2252,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for the execution of sdbinst.exe with command-line arguments of -q and -p. The -q option performs a silent installation with no visible window, status, or warning information. The -p option allows the shim database to contain patches. It will return the count, the first time, and the last time these command-line arguments were seen on each endpoint and by each user. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Persistence', u'Application Shimming'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Persistence", "Application Shimming"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = None identified -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Short Lived Windows Accounts - Rule] type = detection @@ -2262,9 +2262,9 @@ asset_type = Windows confidence = medium explanation = This search looks for Windows Event Logs 4720 (account creation) and 4726 (account deletion) and determines if they happen for the same user within 4 hours of each other. It will report the user and machine that reported the events and the time it first and last saw this activity. how_to_implement = This search requires you to have enabled your Group Management Audit Logs in your Local Windows Security Policy and be ingesting those logs. More information on how to enable them can be found here: http://whatevernetworks.com/auditing-group-membership-changes-in-active-directory/ -annotations = {u'mitre_attack': [u'Valid Accounts'], u'cis20': [u'CIS 16'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Valid Accounts"], "cis20": ["CIS 16"], "nist": ["PR.IP"]} known_false_positives = It is possible that an administrator created and deleted an account in a short time period. Verifying activity with an administrator is advised. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Single Letter Process On Endpoint - Rule] type = detection @@ -2272,9 +2272,9 @@ asset_type = Endpoint confidence = high explanation = This search returns all the processes for each endpoint and user and filters out any process that isn't 5 characters long and ends with .exe. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 2'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 2"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = Single-letter executables are not always malicious. Investigate this activity with your normal incident-response process. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Spectre and Meltdown Vulnerable Systems - Rule] type = detection @@ -2282,9 +2282,9 @@ asset_type = Endpoint confidence = high explanation = This search looks for the three CVEs associated with the Spectre and Meltdown vulnerabilities. how_to_implement = The search requires that you are ingesting your vulnerability-scanner data and that it reports the CVE of the vulnerability identified. -annotations = {u'cis20': [u'CIS 4'], u'nist': [u'ID.RA', u'RS.MI', u'PR.IP', u'DE.CM']} +annotations = {"cis20": ["CIS 4"], "nist": ["ID.RA", "RS.MI", "PR.IP", "DE.CM"]} known_false_positives = It is possible that your vulnerability scanner is not detecting that the patches have been applied. -providing_technologies = [u'Nessus', u'Qualys'] +providing_technologies = ["Nessus", "Qualys"] [savedsearch://ESCU - Spike in File Writes - Rule] type = detection @@ -2292,9 +2292,9 @@ asset_type = Endpoint confidence = low explanation = This search calculates counts the number of file modification events per hour per host in your environment. It then takes the average and standard deviations of those numbers and displays any hosts with more than 20 events that have over four times the standard deviation more than the average number of file modifications. how_to_implement = In order to implement this search, you must populate the Endpoint file-system data model node. This is typically populated via endpoint detection and response products, such as Carbon Black or endpoint data sources such as Sysmon. The data used for this search is typically generated via logs that report reads and writes to the file system. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = It is important to understand that if you happen to install any new applications on your hosts or are copying a large number of files, you can expect to see a large increase of file modifications. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Splunk Enterprise Information Disclosure - Rule] type = detection @@ -2302,9 +2302,9 @@ asset_type = Splunk Server confidence = medium explanation = This search searches Splunk's internal logs for evidence of CVE-2018-11409 exploitation attempts. how_to_implement = The REST endpoint that exposes system information is also necessary for the proper operation of Splunk clustering and instrumentation. Whitelisting your Splunk systems will reduce false positives. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Exploitation of Vulnerability'], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 3', u'CIS 4', u'CIS 18'], u'nist': [u'ID.RA', u'RS.MI', u'PR.PT', u'PR.AC', u'PR.IP', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Exploitation of Vulnerability"], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 3", "CIS 4", "CIS 18"], "nist": ["ID.RA", "RS.MI", "PR.PT", "PR.AC", "PR.IP", "DE.CM"]} known_false_positives = Retrieving server information may be a legitimate API request. Verify that the attempt is a valid request for information. -providing_technologies = [u'Splunk Enterprise'] +providing_technologies = ["Splunk Enterprise"] [savedsearch://ESCU - Suspicious Changes to File Associations - Rule] type = detection @@ -2312,9 +2312,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for changes made to the registry that control Windows file associations. It is typical for users to change the file association to open certain types of files with specific applications. However, when these changes are legitimately performed, they are typically done via the processes explorer.exe or openwith.exe. The search first executes the subsearch that looks at the Registry node, which specifies setting a value in the registry and creates a table of process_id and dest. It then uses those arguments to find out what process and parent process were responsible for making those registry changes. how_to_implement = To successfully implement this search you need to be ingesting information on registry changes that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Registry` nodes. -annotations = {u'mitre_attack': [u'Persistence', u'Change Default File Association'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 8'], u'nist': [u'DE.CM', u'PR.PT', u'PR.IP']} +annotations = {"mitre_attack": ["Persistence", "Change Default File Association"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 8"], "nist": ["DE.CM", "PR.PT", "PR.IP"]} known_false_positives = There may be other processes in your environment that users may legitimately use to modify file associations. If this is the case and you are finding false positives, you can modify the search to add those processes as exceptions. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Suspicious Email Attachment Extensions - Rule] type = detection @@ -2322,9 +2322,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at any email messages with attachments and checks the file names of those attachments against an included lookup file to see if it has a suspicious file extension. how_to_implement = You need to ingest data from emails. Specifically, the sender's address and the file names of any attachments must be mapped to the Email data model. -annotations = {u'mitre_attack': [u'Execution', u'Defense Evasion'], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 3', u'CIS 7', u'CIS 12'], u'nist': [u'DE.AE', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Defense Evasion"], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 3", "CIS 7", "CIS 12"], "nist": ["DE.AE", "PR.IP"]} known_false_positives = None identified -providing_technologies = [u'Microsoft Exchange'] +providing_technologies = ["Microsoft Exchange"] [savedsearch://ESCU - Suspicious File Write - Rule] type = detection @@ -2332,9 +2332,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at files being created or modified in the Endpoint file-system data model. The names of those files are checked against an included lookup file, which contains the names of files associated with malware or attack activity. The search returns any files with matching names, along with a note (also specified in the lookup file) that gives or points to more information about the files. how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file system reads and writes. In addition, this search leverages an included lookup file that contains the names of the files to watch for, as well as a note to communicate why that file name is being monitored. This lookup file can be edited to add or remove file the file names you want to monitor. -annotations = {u'mitre_attack': [], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": [], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = It's possible for a legitimate file to be created with the same name as one noted in the lookup file. Filenames listed in the lookup file should be unique enough that collisions are rare. Looking at the location of the file and the process responsible for the activity can help determine whether or not the activity is legitimate. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] [savedsearch://ESCU - Suspicious Java Classes - Rule] type = detection @@ -2342,9 +2342,9 @@ asset_type = Endpoint confidence = medium explanation = The search leverages HTTP form data from typically POST events that can be captured with Splunk streams or similar wire data capture tools. The search looks for java classes like `processbuilder` and `runtime` are used to create a new process and execute commands inside java, and are synonymous with spawning a shell. There are very exceptional reasons to ever these classes in Java via an HTTP API and hence when seen are highly suspicious. Also, this is a common vectors leverage to exploit Apache Struts. how_to_implement = In order to properly run this search, Splunk needs to ingest data from your web-traffic appliances that serve or sit in the path of your Struts application servers. This can be accomplished by indexing data from a web proxy, or by using network traffic-analysis tools, such as Splunk Stream or Bro. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Exploitation'], u'cis20': [u'CIS 7', u'CIS 12'], u'nist': [u'DE.AE']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Exploitation"], "cis20": ["CIS 7", "CIS 12"], "nist": ["DE.AE"]} known_false_positives = There are no known false positives. -providing_technologies = [u'Splunk Stream', u'Bro', u'Bluecoat', u'Apache'] +providing_technologies = ["Splunk Stream", "Bro", "Bluecoat", "Apache"] [savedsearch://ESCU - Suspicious LNK file launching a process - Rule] type = detection @@ -2352,9 +2352,9 @@ asset_type = Endpoint confidence = high explanation = In this search, we are essentially trying to detect if a LNK file created under the C:\User* or *\Local\Temp\* directory structures is launching a process with in 1 hour of its creation. LNK files or also known as Windows shortcut files are commonly associated with phishing and are a preferred method used for exploitation see: https://www.fireeye.com/blog/threat-research/2017/04/fin7-phishing-lnk.html. how_to_implement = You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or endpoint data sources, such as Sysmon. -annotations = {u'mitre_attack': [u'Spearphishing Attachment'], u'kill_chain_phases': [u'Installation', u'Actions on Objectives'], u'cis20': [u'CIS 7', u'CIS 8'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Spearphishing Attachment"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "cis20": ["CIS 7", "CIS 8"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = This detection should yield little or no false positive results. It is uncommon for LNK files to execute process from temporary or user directories. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Suspicious Reg.exe Process - Rule] type = detection @@ -2362,9 +2362,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for the execution of reg.exe with a parent process of cmd.exe. It then executes a subsearch looking for those cmd.exe processes with a parent that is not explorer.exe. It then joins those two searches to make sure that the reg.exe process is a grandchild of the non explorer.exe process. The search will return the number of such instances and the first and last time this activity has been seen on each endpoint and user. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Modify Registry', u'Disabling Security Tools'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Modify Registry", "Disabling Security Tools"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = It's possible for system administrators to write scripts that exhibit this behavior. If this is the case, the search will need to be modified to filter them out. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Suspicious wevtutil Usage - Rule] type = detection @@ -2372,9 +2372,9 @@ asset_type = confidence = medium explanation = This search looks for execution of wevtutil.exe with command-line arguments that indicate that it has been used to delete the setup, application, security, or system event logs. The search returns the number of times the behavior was observed, the first and last time it was seen, the host exhibiting the behavior and the user context of the process execution. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Indicator Removal on Host'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 6'], u'nist': [u'DE.DP', u'PR.IP', u'PR.PT', u'PR.AC', u'PR.AT', u'DE.AE']} +annotations = {"mitre_attack": ["Defense Evasion", "Indicator Removal on Host"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 6"], "nist": ["DE.DP", "PR.IP", "PR.PT", "PR.AC", "PR.AT", "DE.AE"]} known_false_positives = The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Suspicious writes to System Volume Information - Rule] type = detection @@ -2382,9 +2382,9 @@ asset_type = Windows confidence = medium explanation = This search uses data on file writes captured via Sysmon to watch for writes to the "System Volume Information" folder by processes other than the system process. The search looks for event code 11 in the Sysmon events, which indicates a file-creation event. It then looks for a file created with a path that includes "System Volume Information" and a process ID (PID) other than 4. PID 4 is assigned to the System process on Windows systems. Excluding these writes allows us to filter out legitimate activity. It will report the system where the activity occurred, the path to which the file was written, the process responsible for the write, and the times it first and last saw this activity. how_to_implement = You need to be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {u'mitre_attack': [u'Collection', u'Data Staged'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Collection", "Data Staged"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = It is possible that other utilities or system processes may legitimately write to this folder. Investigate and modify the search to include exceptions as appropriate. -providing_technologies = [u'Sysmon'] +providing_technologies = ["Sysmon"] [savedsearch://ESCU - Suspicious writes to windows Recycle Bin - Rule] type = detection @@ -2392,9 +2392,9 @@ asset_type = Windows confidence = medium explanation = This search uses data on file writes captured via Sysmon to watch for writes to the Recycle Bin by processes other than explorer.exe. The search looks for event code 11 in the Sysmon events, which indicates a file-creation event. Next, it looks for files created with a path that includes the string "$Recycle.Bin" by processes other than explorer.exe, which is the process responsible for copying files to the Recycle Bin on delete. It will report the system where the activity occurred, the path to which the file was written, the process responsible for the write, and the times it first and last saw this activity. how_to_implement = To successfully implement this search you need to be ingesting information on filesystem and process logs responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` nodes. -annotations = {u'mitre_attack': [u'Collection', u'Data Staged'], u'cis20': [u'CIS 8'], u'nist': [u'DE.CM']} +annotations = {"mitre_attack": ["Collection", "Data Staged"], "cis20": ["CIS 8"], "nist": ["DE.CM"]} known_false_positives = Because the Recycle Bin is a hidden folder in modern versions of Windows, it would be unusual for a process other than explorer.exe to write to it. Incidents should be investigated as appropriate. -providing_technologies = [u'Sysmon'] +providing_technologies = ["Sysmon"] [savedsearch://ESCU - System Processes Run From Unexpected Locations - Rule] type = detection @@ -2402,9 +2402,9 @@ asset_type = Endpoint confidence = medium explanation = This search returns all the processes that are not executing out of the C:\Windows\System32 or C:\Windows\SysWOW64 directories. It then uses a regular expression to extract the file name of the running process. Next, it takes the filename and looks it up in a table of files that should normally run out of the C:\Windows\System32 or C:\Windows\SysWOW64 directory. Any matches are then returned. how_to_implement = To successfully implement this search you need to ingest details about process execution from your hosts. Specifically, this search requires the process name and the full path to the process executable. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Masquerading'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Masquerading"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = None identified -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - TOR Traffic - Rule] type = detection @@ -2412,9 +2412,9 @@ asset_type = Endpoint confidence = medium explanation = The search leverages the Enterprise Security Network_Traffic data model to look for network traffic that has been identified as TOR and marked as 'allowed'. how_to_implement = In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search requires the Network_Traffic data model be populated. -annotations = {u'mitre_attack': [u'Command and Control', u'Commonly Used Port', u'Exfiltration'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 9', u'CIS 12'], u'nist': [u'DE.AE']} +annotations = {"mitre_attack": ["Command and Control", "Commonly Used Port", "Exfiltration"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 9", "CIS 12"], "nist": ["DE.AE"]} known_false_positives = None at this time -providing_technologies = [u'Palo Alto Firewall', u'Bro', u'Splunk Stream'] +providing_technologies = ["Palo Alto Firewall", "Bro", "Splunk Stream"] [savedsearch://ESCU - USN Journal Deletion - Rule] type = detection @@ -2422,9 +2422,9 @@ asset_type = Endpoint confidence = medium explanation = This search looks for the execution of fsutil.exe with command-line arguments to delete the USN journal. The search returns the count of the number of times it's seen this process execution with these arguments, the first and last time it's seen this behavior, the hosts it was executed on, and the user context under which it was executed. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Indicator Removal on Host'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 6', u'CIS 8', u'CIS 10'], u'nist': [u'DE.CM', u'PR.PT', u'DE.AE', u'DE.DP', u'PR.IP']} +annotations = {"mitre_attack": ["Defense Evasion", "Indicator Removal on Host"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 6", "CIS 8", "CIS 10"], "nist": ["DE.CM", "PR.PT", "DE.AE", "DE.DP", "PR.IP"]} known_false_positives = None identified -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Uncommon Processes On Endpoint - Rule] type = detection @@ -2432,9 +2432,9 @@ asset_type = Endpoint confidence = high explanation = This search returns the number of times, as well as the first and last time, it has seen every process run for each endpoint and user, and then displays only those processes that you have marked as uncommon in the `uncommon_processes_default.csv` table. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search uses a lookup file `uncommon_processes_default.csv` to track various features of process names that are usually uncommon in most environments. Please consider updating `uncommon_processes_local.csv` to hunt for processes that are uncommon in your environment. -annotations = {u'mitre_attack': [u'Execution', u'Accessibility Features'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 2'], u'nist': [u'ID.AM', u'PR.DS']} +annotations = {"mitre_attack": ["Execution", "Accessibility Features"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 2"], "nist": ["ID.AM", "PR.DS"]} known_false_positives = None identified -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Unsuccessful Netbackup backups - Rule] type = detection @@ -2442,9 +2442,9 @@ asset_type = Endpoint confidence = high explanation = This search looks across the most recent backup events for each host, and returns those messages that indicate there was a backup failure. how_to_implement = To successfully implement this search you need to obtain data from your backup solution, either from the backup logs on your endpoints or from a central server responsible for performing the backups. If you do not use Netbackup, you can modify this search for your specific backup solution. -annotations = {u'cis20': [u'CIS 10'], u'nist': [u'PR.IP']} +annotations = {"cis20": ["CIS 10"], "nist": ["PR.IP"]} known_false_positives = None identified -providing_technologies = [u'Netbackup'] +providing_technologies = ["Netbackup"] [savedsearch://ESCU - Unusually Long Command Line - Rule] type = detection @@ -2452,9 +2452,9 @@ asset_type = confidence = medium explanation = This search calculates the average and standard deviation for the length of the command-lines on each of your endpoints and alerts when a command-line is found with a length over 10 times the standard deviation larger than the average command-line. how_to_implement = You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Please consider changing the value of threshold in the search for reducing false positives. -annotations = {u'mitre_attack': [u'Execution'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 8'], u'nist': [u'PR.PT', u'DE.CM']} +annotations = {"mitre_attack": ["Execution"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 8"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Some legitimate applications start with long command-lines. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Unusually Long Content-Type Length - Rule] type = detection @@ -2462,9 +2462,9 @@ asset_type = Web Server confidence = high explanation = This detection search uses HTTP traffic data captured with Splunk Stream. The search is constructed to use "stream:http" sourcetype and counts of the number of times an HTTP request is received by a destination which the length of the Content-Type header value the client sends the server is greater than 100 characters long. We calculate this content_type_length field and output the results. how_to_implement = This particular search leverages data extracted from Stream:HTTP. You must configure the http stream using the Splunk Stream App on your Splunk Stream deployment server to extract the cs_content_type field. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Exploitation of Vulnerability'], u'kill_chain_phases': [u'Delivery'], u'cis20': [u'CIS 3', u'CIS 4', u'CIS 18', u'CIS 12'], u'nist': [u'ID.RA', u'RS.MI', u'PR.PT', u'PR.IP', u'DE.AE', u'PR.MA', u'DE.CM']} +annotations = {"mitre_attack": ["Defense Evasion", "Exploitation of Vulnerability"], "kill_chain_phases": ["Delivery"], "cis20": ["CIS 3", "CIS 4", "CIS 18", "CIS 12"], "nist": ["ID.RA", "RS.MI", "PR.PT", "PR.IP", "DE.AE", "PR.MA", "DE.CM"]} known_false_positives = Very few legitimate Content-Type fields will have a length greater than 100 characters. -providing_technologies = [u'Splunk Stream'] +providing_technologies = ["Splunk Stream"] [savedsearch://ESCU - WMI Permanent Event Subscription - Rule] type = detection @@ -2472,9 +2472,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers are increasingly abusing Windows Management Infrastructure (WMI) for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for the creation of a WMI event subscription by watching for Windows event ID 5861. how_to_implement = To successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation', u'Persistence', u'Windows Management Instrumentation Event Subscription'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation", "Persistence", "Windows Management Instrumentation Event Subscription"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Although unlikely, administrators may use event subscriptions for legitimate purposes. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - WMI Permanent Event Subscription - Sysmon - Rule] type = detection @@ -2482,9 +2482,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers are increasingly abusing Windows Management Infrastructure (WMI) for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for the creation of a WMI event subscription by watching for Sysmon event ID 21. how_to_implement = To successfully implement this search, you must be collecting Sysmon data using Sysmon version 6.1 or greater and have Sysmon configured to generate alerts for WMI activity. In addition, you must have at least version 6.0.4 of the Sysmon TA installed to properly parse the fields. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation', u'Persistence', u'Windows Management Instrumentation Event Subscription'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation", "Persistence", "Windows Management Instrumentation Event Subscription"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Although unlikely, administrators may use event subscriptions for legitimate purposes. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - WMI Temporary Event Subscription - Rule] type = detection @@ -2492,9 +2492,9 @@ asset_type = Endpoint confidence = medium explanation = Attackers are increasingly abusing Windows Management Infrastructure (WMI) for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for the creation of a WMI temporary event subscription by watching for Windows event ID 5860. how_to_implement = To successfully implement this search, you must be ingesting the Windows WMI activity logs. This can be done by adding a stanza to inputs.conf on the system generating logs with a title of [WinEventLog://Microsoft-Windows-WMI-Activity/Operational]. -annotations = {u'mitre_attack': [u'Execution', u'Windows Management Instrumentation', u'Persistence', u'Windows Management Instrumentation Event Subscription'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5'], u'nist': [u'PR.PT', u'PR.AT', u'PR.AC', u'PR.IP']} +annotations = {"mitre_attack": ["Execution", "Windows Management Instrumentation", "Persistence", "Windows Management Instrumentation Event Subscription"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5"], "nist": ["PR.PT", "PR.AT", "PR.AC", "PR.IP"]} known_false_positives = Some software may create WMI temporary event subscriptions for various purposes. The included search contains an exception for two of these that occur by default on Windows 10 systems. You may need to modify the search to create exceptions for other legitimate events. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Web Fraud - Account Harvesting - Rule] type = detection @@ -2502,9 +2502,9 @@ asset_type = Account confidence = medium explanation = When a fraudster is setting the stage for a campaign, they will often create many user accounts on the website. This is a simple example of how to detect a many-account creation hosted on a Magento2 e-commerce platform, where the fraudster is using email addresses from a single email domain. how_to_implement = We start with a dataset that provides visibility into the email address used for the account creation. In this example, we are narrowing our search down to the single web page that hosts the Magento2 e-commerce platform (via URI) used for account creation, the single http content-type to grab only the user's clicks, and the http field that provides the username (form_data), for performance reasons. After we have the username and email domain, we look for numerous account creations per email domain. Common data sources used for this detection are customized Apache logs or Splunk Stream. -annotations = {u'mitre_attack': [u'Create Account'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 16'], u'nist': [u'DE.CM', u'DE.DP']} +annotations = {"mitre_attack": ["Create Account"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 16"], "nist": ["DE.CM", "DE.DP"]} known_false_positives = As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamolous behavior. This search will need to be customized to fit your environment—improving its fidelity by counting based on something much more specific, such as a device ID that may be present in your dataset. Consideration for whether the large number of registrations are occuring from a first-time seen domain may also be important. Extending the search window to look further back in time, or even calculating the average per hour/day for each email domain to look for an anomalous spikes, will improve this search. You can also use Shannon entropy or Levenshtein Distance (both courtesy of URL Toolbox) to consider the randomness or similarity of the email name or email domain, as the names are often machine-generated. -providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Bro'] +providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Bro"] [savedsearch://ESCU - Web Fraud - Anomalous User Clickspeed - Rule] type = detection @@ -2512,9 +2512,9 @@ asset_type = account confidence = medium explanation = It's suspicious when someone or something is moving throughout your website too quickly or with a perfect click cadence. Fortunately, it's easy to detect by calculating the time between clicks for each session and highlighting the anomalous behavior. how_to_implement = Start with a dataset that allows you to see clickstream data for each user click on the website. That data must have a time stamp and must contain a reference to the session identifier being used by the website. This ties the clicks together into clickstreams. This value is usually found in the http cookie. With a bit of tuning, a version of this search could be used in high-volume scenarios, such as scraping, crawling, application DDOS, credit-card testing, account takeover, etc. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. -annotations = {u'mitre_attack': [u'Valid Accounts'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 6'], u'nist': [u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Valid Accounts"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 6"], "nist": ["DE.AE", "DE.CM"]} known_false_positives = As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosly written detections that simply detect anamoluous behavior. -providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Bro'] +providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Bro"] [savedsearch://ESCU - Web Fraud - Password Sharing Across Accounts - Rule] type = detection @@ -2522,9 +2522,9 @@ asset_type = account confidence = medium explanation = A common password across user accounts generally indicates that the users are choosing poor passwords or that a fraudster has a common password across multiple accounts embedded within a script. The search will extract the username and password information from the form_data field, then calculate the number and values for usernames that have the same passwords. Finally, it outputs the values where the unique usernames sharing passwords are greater than 5 how_to_implement = We need to start with a dataset that allows us to see the values of usernames and passwords that users are submitting to the website hosting the Magento2 e-commerce platform (commonly found in the HTTP form_data field). A tokenized or hashed value of a password is acceptable and certainly preferable to a clear-text password. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. -annotations = {u'cis20': [u'CIS 16'], u'nist': [u'DE.DP']} +annotations = {"cis20": ["CIS 16"], "nist": ["DE.DP"]} known_false_positives = As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamoluous behavior. -providing_technologies = [u'Splunk Stream', u'Palo Alto Firewall', u'Bro'] +providing_technologies = ["Splunk Stream", "Palo Alto Firewall", "Bro"] [savedsearch://ESCU - Web Servers Executing Suspicious Processes - Rule] type = detection @@ -2532,9 +2532,9 @@ asset_type = Web Server confidence = medium explanation = This detection search uses the Enterprise Security Endpoint data model. The search uses tstats to search within an accelerated data model to find suspicious applications or processes such as whoami, ping, iptables, wget, service, or curl, running on hosts which are marked as web servers in the Assets and Identity Framework of ES. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. In addition, web servers will need to be identified in the Assets and Identity Framework of Enterprise Security. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Exploitation of Vulnerability', u'Execution', u'Discovery', u'System Information Discovery'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3'], u'nist': [u'PR.IP']} +annotations = {"mitre_attack": ["Defense Evasion", "Exploitation of Vulnerability", "Execution", "Discovery", "System Information Discovery"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3"], "nist": ["PR.IP"]} known_false_positives = Some of these processes may be used legitimately on web servers during maintenance or other administrative tasks. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Windows Event Log Cleared - Rule] type = detection @@ -2542,9 +2542,9 @@ asset_type = Endpoint confidence = high explanation = This search looks at the Windows security and system event logs. EventCode 1002 in the security log indicates that the log has been cleared, EventCode 1000 in the security log indicates the event logging service has been shut down, and EventCode 104 in the system log indicates the application log has been cleared. If any of these events are found, a notable will be generated. how_to_implement = To successfully implement this search, you need to be ingesting Windows event logs from your hosts. -annotations = {u'mitre_attack': [u'Defense Evasion', u'Indicator Removal on Host'], u'kill_chain_phases': [u'Actions on Objectives'], u'cis20': [u'CIS 3', u'CIS 5', u'CIS 6'], u'nist': [u'DE.DP', u'PR.IP', u'PR.AC', u'PR.AT', u'DE.AE']} +annotations = {"mitre_attack": ["Defense Evasion", "Indicator Removal on Host"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 3", "CIS 5", "CIS 6"], "nist": ["DE.DP", "PR.IP", "PR.AC", "PR.AT", "DE.AE"]} known_false_positives = It is possible that these logs may be legitimately cleared by Administrators. -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Windows hosts file modification - Rule] type = detection @@ -2552,9 +2552,9 @@ asset_type = Endpoint confidence = high explanation = The hosts file is present on both Windows and Linux endpoints. The purpose of the hosts file is to provide a mapping between hostnames and IP addresses, the same way DNS is used to provide such a mapping. However, the information in the hosts file takes precedence over information received via DNS and a DNS query will not be issued if the hostname of interest is found in the hosts file. As such, attackers have been observed adding entries to the host file to override any DNS resolution. For this reason, it is useful to monitor for changes to this file, which typically do not occur very often in legitimate cases. how_to_implement = To successfully implement this search, you must be ingesting data that records the file-system activity from your hosts to populate the Endpoint.Filesystem data model node. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or by other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. -annotations = {u'mitre_attack': [u'Command and Control', u'Exfiltration'], u'kill_chain_phases': [u'Command and Control'], u'cis20': [u'CIS 3', u'CIS 8', u'CIS 12'], u'nist': [u'PR.IP', u'PR.PT', u'PR.AC', u'DE.AE', u'DE.CM']} +annotations = {"mitre_attack": ["Command and Control", "Exfiltration"], "kill_chain_phases": ["Command and Control"], "cis20": ["CIS 3", "CIS 8", "CIS 12"], "nist": ["PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]} known_false_positives = There may be legitimate reasons for system administrators to add entries to this file. -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon"] ### END DETECTIONS ### @@ -2912,217 +2912,217 @@ type = support explanation = This search outputs the interesting processes lookup table and filters out all processes in the table that haven't already been inserted by ESCU. It then appends to those results all the processes currently identified by ESCU that should be prohibited. Next, it fills in the required fields with processes identified by ESCU, and then writes the results back to the interesting process lookup table. This is done so any new processes identified that should be prohibited will be added to the lookup table without creating any duplicate entries. how_to_implement = This search should be run on each new install of ESCU. known_false_positives = -providing_technologies = [u'Splunk Enterprise Security'] +providing_technologies = ["Splunk Enterprise Security"] [savedsearch://ESCU - Baseline of API Calls per User ARN] type = support explanation = This search returns all log events that are API calls, pulls out the ARN that initiated each call, and collects them in one-hour groupings. Next, it calculates the number of API calls made per ARN per hour. For each ARN, it calculates the average and standard deviation of this count on a per-hour basis. It also includes the number of data points each ARN had. This table is then stored in a lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Baseline of Network ACL Activity by ARN] type = support explanation = Use this search to create a baseline for API calls related to network ACLs for the users who initiated this activity. It returns all logged API calls for network activity, pulls out the ARN that initiated each call, and collects the eventNames in one-hour groupings. Next, it calculates the number of API calls made per ARN per-hour. For each ARN, it calculates the average and standard deviation of this count on a per-hour basis. It also includes the number of data points for each ARN. This table is stored in a lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. To add or remove API event names for network ACLs, edit the macro NetworkACLEvents. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Baseline of S3 Bucket deletion activity by ARN] type = support explanation = Use this search to create a baseline for API calls related to deleting an S3 bucket, grouped by the users who initiated this activity. It returns all logged API calls for S3 bucket-deletion activity and then pulls out the ARN that initiated each call. Next, it calculates the number of API calls made per ARN per hour. For each ARN, it calculates the average and standard deviation of this count on a per-hour basis. It also includes the number of data points for each ARN. This table is stored in a lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Baseline of Security Group Activity by ARN] type = support explanation = Use this search to create a baseline for API calls related to security groups by the users who initiated this activity. It returns all logged API calls for all security-group-related activity, pulls out the ARN that initiated each call, and collects the eventNames in one-hour groupings. Next, it calculates the number of API calls made per ARN per hour. For each ARN, it calculates the average and standard deviation of this count on a per-hour basis. It also includes the number of data points for each ARN. This table is stored in a lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. To add or remove API event names for security groups, edit the macro securityGroupAPIs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Baseline of blocked outbound traffic from AWS] type = support explanation = Use this search to create a baseline of blocked outbound network connections by each source IP in your AWS environment. This search returns all log events that correspond to a blocked outbound network connection, extracts the source IP from where the outbound connection was initiated, and collects the events in one-hour groupings. Next, it calculates the number of outbound connections blocked per hour. For each source IP, it calculates the average and standard deviation of this count on a per-hour basis. It also includes the number of data points each source IP had. This table is then stored in a lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your VPC flow logs.. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Count of Unique IPs Connecting to Ports] type = support explanation = For each port being accessed on the network, this search gives the total number of connections observed, and the number of unique IP addresses making those connections. how_to_implement = To successfully implement this search, you must be ingesting network traffic, and populating the Network_Traffic data model. known_false_positives = -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Count of assets by category] type = support explanation = This search gives you the number and the names of the hosts of each host in your environment by category. It will then sort them by the count. how_to_implement = To successfully implement this search you must first leverage the Assets and Identity framework in Enterprise Security to populate your assets_by_str.csv file which should then be mapped to the Identity_Management data model. The Identity_Management data model will contain a list of known authorized company assets. Ensure that all inventoried systems are constantly vetted and updated. known_false_positives = -providing_technologies = [u'Splunk Enterprise Security'] +providing_technologies = ["Splunk Enterprise Security"] [savedsearch://ESCU - Create a list of approved AWS service accounts] type = support explanation = We first look for all successful CloudTrail API activity caused by types of user accounts and then remove all the events caused by users in the Identity table. This generates a list of accounts--typically service accounts--configured in your AWS environment. We output this list of service accounts to aws_service_accounts.csv. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Please validate the service account entires in aws_service_accounts.csv, which is a lookup file created as a result of running this support search. Please remove the entries of service accounts that are not legitimate. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - DNSTwist Domain Names] type = support explanation = This search starts with the dnstwist command consuming domains from a file called domains.csv in the DA-ESS-SOC/lookups directory. This search then adds a domain\_abuse=true term to each permutation, removes all the valid domain names and stores all that information into a lookup file that is used in the associated detection search. Alternatively domain dnstwist permutations can be calculated from domains in the `cim_corporate_email_domains.csv` and `cim_corporate_web_domains.csv` lookups located in **Splunk\_SA\_CIM** using argument `populate_from_cim=true`. Also an individual domain can be passed using argument `domain=` how_to_implement = To successfully implement this search you need to update the file called domains.csv in the DA-ESS-SOC/lookup directory. Or `cim_corporate_email_domains.csv` and `cim_corporate_web_domains.csv` from **Splunk\_SA\_CIM**. known_false_positives = -providing_technologies = [u'Splunk Enterprise'] +providing_technologies = ["Splunk Enterprise"] [savedsearch://ESCU - Discover DNS records] type = support explanation = Discover the DNS records and their answers for domains owned by the company using network traffic events. The discovered events are exported as a lookup named `discovered_dns_records.csv` how_to_implement = To successfully implement this search, you must be ingesting DNS logs, and populating the Network_Resolution data model. Also make sure that the cim_corporate_web_domains and cim_corporate_email_domains lookups are populated with the domains owned by your corporation known_false_positives = Please vet the lookup created by this baseline search -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Identify Systems Creating Remote Desktop Traffic] type = support explanation = This search counts the numbers of times the system has tried to connect to another system on TCP/3389, the default port used for RDP traffic. how_to_implement = To successfully implement this search, you must ingest network traffic and populate the Network_Traffic data model. known_false_positives = -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Identify Systems Receiving Remote Desktop Traffic] type = support explanation = This search counts the numbers of times the system has received a connection to TCP/ 3389, the default port used for RDP traffic. how_to_implement = To successfully implement this search you must ingest network traffic and populate the Network_Traffic data model. If a system receives a lot of remote desktop traffic, you can apply the category common_rdp_destination to it. known_false_positives = -providing_technologies = [u'Splunk Stream', u'Bro'] +providing_technologies = ["Splunk Stream", "Bro"] [savedsearch://ESCU - Identify Systems Using Remote Desktop] type = support explanation = This search counts the numbers of times the remote desktop process, mstsc.exe, has run on each system. It does this by looking for the process name in the Endpoint data model. how_to_implement = To successfully implement this search you must be ingesting endpoint data that records process activity. known_false_positives = -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Monitor Successful Backups] type = support explanation = This search gives you the count and the hostname of all the systems that had a successful backup each day. how_to_implement = To successfully implement this search you must be ingesting your backup logs. known_false_positives = -providing_technologies = [u'Netbackup'] +providing_technologies = ["Netbackup"] [savedsearch://ESCU - Monitor Unsuccessful Backups] type = support explanation = This search gives you the count and hostname of all the systems that had a backup failure each day how_to_implement = To successfully implement this search you must be ingesting your backup logs. known_false_positives = -providing_technologies = [u'Netbackup'] +providing_technologies = ["Netbackup"] [savedsearch://ESCU - Previously Seen AWS Cross Account Activity] type = support explanation = In this support search, we look for AssumeRole events where the requesting account is different from the requested account. The first and last times these events are seen are written to a lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Validate the user name entries in previously_seen_aws_cross_account_activity.csv, a lookup file created by this support search. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen AWS Provisioning Activity Sources] type = support explanation = This search includes any event name that begins with "run" or "create," and then determines the first and last time these events were seen for each IP address that initiated the action. The search then consults a GeoIP database to determine the physical location of this IP address. This table outputs to a file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen AWS Regions] type = support explanation = In this support search, we create a table of the first time (earliest) and most recent time (latest) that this region has been seen in our dataset, grouped by the value awsRegion. We only look for those events where an instance has been started. All of these entries will be added to the previously_seen_aws_regions.csv lookup file, which will act like a baseline for detections. Please validate the entries of region names in the lookup file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen EC2 AMIs] type = support explanation = In this support search, we create a table of the earliest and latest time that a specific AMI ID has been seen. This table is then outputted to a csv file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen EC2 Instance Types] type = support explanation = In this support search, we create a table of the earliest and latest time that a specific EC2 instance type has been seen. The instanceType request field is not required and defaults to m1.small, so any time this field is null, the search defaults the field to m1.small. This table is then outputted to a csv file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen EC2 Launches By User] type = support explanation = In this support search, we create a table of the earliest and latest times that an ARN has launched a EC2 instance. This table is then outputted to a csv file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen EC2 Modifications By User] type = support explanation = In this support search, we create a table of the earliest and latest times that an ARN has modified a EC2 instance. The list of APIs that modify an EC2 are defined in the ec2ModificationAPIs macro for ease of use. This table is then outputted to a file. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS version (4.4.0 or later), then configure your CloudTrail inputs. To add or remove APIs that modify an EC2 instance, edit the macro ec2ModificationAPIs. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously Seen Running Windows Services] type = support explanation = In this support search, we look for Windows system-event code that indicates a status change of a Windows service. It extracts both the name of the service and the action taken by the service from the logs. It keeps only services that have entered the running state. Finally, it finds the first time the service has been seen running across the enterprise and writes that file to a lookup table. how_to_implement = While this search does not require you to adhere to Splunk CIM, you must be ingesting your Windows security-event logs for it to execute successfully. known_false_positives = -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Previously seen API call per user roles in CloudTrail] type = support explanation = In this support search, we are looking for successful API calls made by user roles within your AWS infrastructure. The intent is to create an initial baseline cache of names of the API calls per security role for the previous 30 days--including the earliest and latest times seen in our dataset--grouped by the value of user role and the name of the API call. It is also worth noting that the role of a particular user is parsed as "userName" in the CloudTrail logs. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Please validate the user role entries in previously_seen_api_calls_from_user_roles.csv, which is a lookup file created as a result of running this support search. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously seen S3 bucket access by remote IP] type = support explanation = In this support search, we are looking for successful S3 bucket-access attempts made from remote IPs. The intent is to create an initial baseline cache of remote IP addresses per bucket name for the previous 30 days--including the earliest and latest times seen in our dataset--grouped by the value of remote IP and the name of the S3 bucket. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your S3 access-logs inputs. You must validate the remote IP and bucket name entries in previously_seen_S3_access_from_remote_ip.csv, which is a lookup file created as a result of running this support search. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Previously seen command line arguments] type = support explanation = In this support search, we look for command-line arguments using the parameter /c to execute processes and create an initial baseline cache for the previous 30 days. This will include the earliest and latest times a particular command-line argument is seen in our dataset, grouped by the command-line value. how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must be ingesting logs with both the process name and command line from your endpoints. The complete process name with command-line arguments are mapped to the "process" field in the Endpoint data model. known_false_positives = -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Previously seen users in CloudTrail] type = support explanation = In this support search, we look for console login events by a particular user and create an initial baseline cache for the previous seven days, including the earliest and latest times a particular user ARN is seen in our dataset, grouped by the ARN value. how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail inputs. Please validate the user name entries in previously_seen_users_console_logins.csv, which is a lookup file created as a result of running this support search. known_false_positives = -providing_technologies = [u'AWS'] +providing_technologies = ["AWS"] [savedsearch://ESCU - Systems Ready for Spectre-Meltdown Windows Patch] type = support explanation = This search looks to see if a registry key was created at HKLM\Software\Microsoft\Windows\CurrentVersion\QualityCompat. It will tell you when it was created and, if possible, what process created it. how_to_implement = You need to be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. known_false_positives = -providing_technologies = [u'Carbon Black Response', u'CrowdStrike Falcon', u'Sysmon', u'Tanium', u'Ziften'] +providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Sysmon", "Tanium", "Ziften"] [savedsearch://ESCU - Windows Updates Install Failures] type = support explanation = This search gives you the count of the number of systems that attempted and failed to install a Windows update each day. how_to_implement = You must be ingesting your Windows Update Logs known_false_positives = -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] [savedsearch://ESCU - Windows Updates Install Successes] type = support explanation = This search gives you the count and name of all the systems that had a successful update applied each day how_to_implement = You must be ingesting your Windows Update Logs known_false_positives = -providing_technologies = [u'Microsoft Windows'] +providing_technologies = ["Microsoft Windows"] ### END BASELINES ###