Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-03-06 10:54:42 -08:00
committed by GitHub
63 changed files with 2233 additions and 71 deletions
@@ -20,4 +20,4 @@
sourcetype: "{{ sourcetype }}"
rename-source: "{{ source }}"
index: "{{ index }}"
status_code: 201
status_code: 201
@@ -142,9 +142,14 @@ setup_schema = {
"URL_TOOLBOX": {
"app_number": 2734,
"app_version": "1.9.2",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz",
},
"SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": {
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz"
},
"SPLUNK_TA_FIX_WINDOWS":{
"app_number": 9999,
"app_version": "1.0.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz"
},
"SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": {
"app_number": 3110,
"app_version": "4.5.2",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_452.tgz",
@@ -1,9 +1,109 @@
{
"apps": {
"ADD_ON_FOR_LINUX_SYSMON": {
"app_number": 6176,
"app_version": "1.0.4",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz"
"Splunk Add-on for CrowdStrike FDR": {
"app_number": 5579,
"app_version": "1.2.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_120.tgz"
},
"ADD_ON_FOR_LINUX_SYSMON": {
"app_number": 6176,
"app_version": "1.0.4",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz"
},
"PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": {
"app_number": 2757,
"app_version": "7.1.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/palo-alto-networks-add-on-for-splunk_710.tgz"
},
"PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": {
"app_number": 2882,
"app_version": "3.0.2",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/python-for-scientific-computing-for-linux-64-bit_302.tgz"
},
"SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE": {
"app_number": 3719,
"app_version": "1.3.2",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-amazon-kinesis-firehose_132.tgz"
},
"SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": {
"app_number": 4055,
"app_version": "4.0.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_400.tgz"
},
"SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": {
"app_number": 742,
"app_version": "8.5.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850.tgz"
},
"SPLUNK_ADD_ON_FOR_NGINX": {
"app_number": 3258,
"app_version": "3.1.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-nginx_310.tgz"
},
"SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS": {
"app_number": 5238,
"app_version": "8.1.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-forwarders_810.tgz"
},
"SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA": {
"app_number": 5234,
"app_version": "8.1.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-wire-data_810.tgz"
},
"SPLUNK_ADD_ON_FOR_SYSMON": {
"app_number": 5709,
"app_version": "3.0.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-sysmon_300.tgz"
},
"SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": {
"app_number": 833,
"app_version": "8.6.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_860.tgz"
},
"SPLUNK_APP_FOR_STREAM": {
"app_number": 1809,
"app_version": "8.1.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-app-for-stream_810.tgz"
},
"SPLUNK_TA_FIX_WINDOWS":{
"app_number": 9999,
"app_version": "1.0.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz"
},
"SPLUNK_COMMON_INFORMATION_MODEL": {
"app_number": 1621,
"app_version": "5.0.1",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_501.tgz"
},
"SPLUNK_ES_CONTENT_UPDATE": {
"app_number": 3449,
"app_version": null,
"local_path": null
},
"SPLUNK_MACHINE_LEARNING_TOOLKIT": {
"app_number": 2890,
"app_version": "5.3.1",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-machine-learning-toolkit_531.tgz"
},
"SPLUNK_TA_FOR_ZEEK": {
"app_number": 5466,
"app_version": "1.0.5",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-zeek_105.tgz"
},
"URL_TOOLBOX": {
"app_number": 2734,
"app_version": "1.9.2",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz"
},
"SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": {
"app_number": 3088,
"app_version": "4.0.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-cloud-platform_400.tgz"
},
"SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": {
"app_number": 3110,
"app_version": "2.3.0",
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-workspace_230.tgz"
},
"PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": {
"app_number": 2757,
@@ -49,6 +49,7 @@ tags:
- T1586.003
- T1110
- T1110.003
- T1110.004
nist:
- DE.CM
observable:
@@ -42,6 +42,7 @@ tags:
- T1586
- T1586.003
- T1556
- T1556.006
nist:
- DE.CM
observable:
@@ -0,0 +1,76 @@
name: Disabling Windows Local Security Authority Defences via Registry
id: 45cd08f8-a2c9-4f4e-baab-e1a0c624b0ab
version: 1
date: '2022-09-09'
author: Dean Luxton
type: TTP
datamodel:
- Endpoint
description: This detection looks for the deletion of registry keys which disable LSA protection and MS Defender Device Guard.
search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Endpoint.Registry
where Registry.registry_path IN ("*\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\LsaCfgFlags",
"*\\SOFTWARE\\Policies\\Microsoft\\Windows\\DeviceGuard\\*", "*\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\RunAsPPL")
Registry.action IN (deleted, unknown) by Registry.action Registry.registry_path
Registry.process_guid
| `drop_dm_object_name(Registry)`
| join type=outer process_guid [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by Processes.user Processes.process_name Processes.process
Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid
| `drop_dm_object_name(Processes)`]
| table _time action dest user parent_process_name parent_process process_name process
process_guid registry_path | `disabling_windows_local_security_authority_defences_via_registry_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
used for this search is typically generated via logs that report reads and writes
to the registry.
known_false_positives: Potential to be triggered by an administrator disabling protections for troubleshooting purposes.
references:
- https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection
- https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-manage
tags:
analytic_story:
- Windows Defence Evasion Tactics
- Windows Registry Abuse
asset_type: Endpoint
cis20:
- CIS 5
- CIS 6
- CIS 16
confidence: 100
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_lsa_protection/windows-sysmon.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_credential_guard/windows-sysmon.log
impact: 60
kill_chain_phases:
- Actions on Objectives
message: An attempt to disable Windows LSA defences was detected on $dest$. The reg key $registry_path$ was deleted by $user$.
mitre_attack_id:
- T1556
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.action
- Registry.registry_path
- Registry.dest
- Registry.user
risk_score: 60
security_domain: endpoint
@@ -1,7 +1,7 @@
name: Impacket Lateral Movement Commandline Parameters
id: 8ce07472-496f-11ec-ab3b-3e22fbd008af
version: 2
date: '2022-01-18'
version: 3
date: '2023-02-24'
author: Mauricio Velazco, Splunk
type: TTP
datamodel:
@@ -14,11 +14,10 @@ description: This analytic looks for the presence of suspicious commandline para
scripts leverage administrative shares and hardcoded parameters that can be used
as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets
tools for lateral movement and remote code execution.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*/c* \\\\127.0.0.1\\*"
OR Processes.process= "*/c* 2>&1") by Processes.dest Processes.user Processes.parent_process_name
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe (Processes.process = "*/Q /c * \\\\127.0.0.1\\*$*" AND Processes.process IN ("*2>&1*","*2>&1*")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `impacket_lateral_movement_commandline_parameters_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
@@ -0,0 +1,75 @@
name: Notepad with no Command Line Arguments
id: 5adbc5f1-9a2f-41c1-a810-f37e015f8179
version: 1
date: '2023-02-22'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies behavior related to default SliverC2 framework where it will inject into Notepad.exe and spawn Notepad.exe with no command line arguments. In testing, this is a common procedure for SliverC2 usage, however may be modified or changed.
From Microsoft, "The Sideload, SpawnDll, and Execute-Assembly commands spawn and inject into notepad.exe by default. The following query finds process creation events where the same process creates and injects into notepad.exe within 10 seconds."
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=notepad.exe AND Processes.action!="blocked" by host _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.parent_process
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| regex process="(?i)(notepad\.exe.{0,4}$)"
| `notepad_with_no_command_line_arguments_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives may be present and filtering may need to occur based on organization endpoint behavior.
references:
- https://www.microsoft.com/en-us/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/
- https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors#Purple-Team-Section
tags:
analytic_story:
- BishopFox Sliver Adversary Emulation Framework
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 70
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/notepad_windows-sysmon.log
impact: 50
kill_chain_phases:
- Exploitation
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ with no command line arguments.
mitre_attack_id:
- T1055
nist:
- DE.CM
observable:
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 35
security_domain: endpoint
@@ -57,6 +57,7 @@ tags:
- Qakbot
- Chaos Ransomware
- AsyncRAT
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 8
@@ -47,21 +47,28 @@ tags:
impact: 70
kill_chain_phases:
- Actions on Objectives
message: Suspicious $Processes.process_path.file_path$ process running with an uncommon
parent process $Processes.parent_process_name$
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to add a registry entry.
mitre_attack_id:
- T1112
nist:
- DE.CM
observable:
- name: dest
type: Endpoint
- name: user
type: User
role:
- Victim
- name: Processes.process_path.file_path
type: File Name
- name: dest
type: Hostname
role:
- Attacker
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -78,4 +85,4 @@ tags:
risk_score: 35
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
- Splunk_TA_microsoft_sysmon
@@ -1,20 +1,18 @@
name: Suspicious Regsvr32 Register Suspicious Path
id: 62732736-6250-11eb-ae93-0242ac130002
version: 2
date: '2021-01-28'
version: 3
date: '2023-03-02'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: Adversaries may abuse Regsvr32.exe to proxy execution of malicious code
by using non-standard file extensions to load malciious DLLs. Upon investigating,
by using non-standard file extensions to load DLLs. Upon investigating,
look for network connections to remote destinations (internal or external). Review
additional parrallel processes and child processes for additional activity.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata*
OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll
Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user
Processes.parent_process Processes.process_name Processes.process Processes.original_file_name
as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process IN ("*\\appdata\\*", "*\\programdata\\*","*\\windows\\temp\\*") NOT (Processes.process IN ("*.dll*", "*.ax*", "*.ocx*"))
by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name
Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_regsvr32_register_suspicious_path_filter`'
how_to_implement: You must be ingesting endpoint data that tracks process activity,
@@ -54,22 +52,29 @@ tags:
impact: 70
kill_chain_phases:
- Actions on Objectives
message: Suspicious $Processes.process_path.file_path$ process potentially loading
malicious code
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to evade detection by using a non-standard file extension.
mitre_attack_id:
- T1218
- T1218.010
nist:
- DE.CM
observable:
- name: dest
type: Endpoint
- name: user
type: User
role:
- Victim
- name: Processes.process_path.file_path
type: File Name
- name: dest
type: Hostname
role:
- Attacker
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -90,4 +95,4 @@ tags:
risk_score: 35
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
- Splunk_TA_microsoft_sysmon
@@ -52,7 +52,7 @@ tags:
impact: 70
kill_chain_phases:
- Actions on Objectives
message: $Processes.process_path.file_path$ process potentially loading malicious
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to register a DLL.
code
mitre_attack_id:
- T1218
@@ -61,14 +61,22 @@ tags:
- PR.PT
- DE.CM
observable:
- name: dest
type: Endpoint
- name: user
type: User
role:
- Victim
- name: Processes.process_path.file_path
type: File Name
- name: dest
type: Hostname
role:
- Attacker
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -89,4 +97,4 @@ tags:
risk_score: 35
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
- Splunk_TA_microsoft_sysmon
@@ -0,0 +1,76 @@
name: Windows AD AdminSDHolder ACL Modified
id: 00d877c3-7b7b-443d-9562-6b231e2abab9
version: 1
date: '2022-11-15'
author: Mauricio Velazco, Splunk
type: TTP
datamodel: []
description: The following analytic identifies the modification of the Access Control List for the AdminSDHolder object within a Windows domain. Specifically, the
detection triggers on the addition of a new rule to the existing ACL. AdminSDHolder is an object located in the System Partition in Active Directory and is used as a
security template for objects that are members of certain privileged groups. Objects in these groups are enumerated and any objects with security descriptors that dont
match the AdminSDHolder ACL are flagged for updating. The Security Descriptor propagator (SDProp) process runs every 60 minutes on the PDC Emulator and re-stamps the object
Access Control List (ACL) with the security permissions set on the AdminSDHolder. An adversary who has obtained privileged access to a Windows Domain may modify the AdminSDHolder
ACL to establish persistence and allow an unprivileged user to take control of a domain.
search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=nTSecurityDescriptor OperationType="%%14674" ObjectDN="CN=AdminSDHolder,CN=System*"
| rex field=AttributeValue max_match=10000 "A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;(?P<added_user_sid>S-1-[0-59]-\d{2}-\d{8,10}-\d{8,10}-\d{8,10}-[1-9]\d{3})\)"
| stats values(added_user_sid) by _time, Computer, SubjectUserName, ObjectDN
| `windows_ad_adminsdholder_acl_modified_filter`'
how_to_implement: To successfully implement this search, you ned to be ingesting eventcode
`5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes`
within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for the AdminSDHolder object in order to log modifications.
known_false_positives: Adding new users or groups to the AdminSDHolder ACL is not usual. Filter as needed
references:
- https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory
- https://social.technet.microsoft.com/wiki/contents/articles/22331.adminsdholder-protected-groups-and-security-descriptor-propagator.aspx
- https://adsecurity.org/?p=1906
- https://pentestlab.blog/2022/01/04/domain-persistence-adminsdholder/
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136
- https://learn.microsoft.com/en-us/windows/win32/secauthz/access-control-lists
- https://medium.com/@cryps1s/detecting-windows-endpoint-compromise-with-sacls-cd748e10950
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 70
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/adminsdholder_modified/windows-security.log
impact: 80
kill_chain_phases:
- Installation
- Actions on Objectives
message: The AdminSDHolder domain object has been modified on $Computer$ by $SubjectUserName$
mitre_attack_id:
- T1546
nist:
- DE.CM
observable:
- name: SubjectUserName
type: User
role:
- Attacker
- name: Computer
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- AttributeLDAPDisplayName
- OperationType
- ObjectDN
- Computer
- SubjectUserName
- AttributeValue
risk_score: 56
security_domain: endpoint
@@ -0,0 +1,75 @@
name: Windows AD Cross Domain SID History Addition
id: 41bbb371-28ba-439c-bb5c-d9930c28365d
version: 1
date: '2022-11-17'
author: Dean Luxton
type: TTP
datamodel: []
description: The following analytic looks for changes to the sIDHistory AD attribute of user or computer objects within different domains.
The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access
continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries for inter-domain privilege escalation and persistence.
search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory IN ("%%1793", -)
| rex field=SidHistory "(^%{|^)(?P<SidHistoryMatch>.*)(\-|\\\)"
| rex field=TargetSid "^(?P<TargetSidmatch>.*)(\-|\\\)"
| where SidHistoryMatch!=TargetSidmatch AND SidHistoryMatch!=TargetDomainName
| rename TargetSid as userSid
| table _time action status host user userSid SidHistory Logon_ID src_user
| `windows_ad_cross_domain_sid_history_addition_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting eventcodes
`4738` and `4742`. The Advanced Security Audit policy settings
`Audit User Account Management` and `Audit Computer Account Management`
within `Account Management` all need to be enabled.
known_false_positives: Domain mergers and migrations may generate large volumes of false positives for this analytic.
references:
- https://adsecurity.org/?p=1772
- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN
- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
- CIS 16
confidence: 80
context:
- Source:AD
- Stage:Persistence
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: Active Directory SID History Attribute was added to $user$ by $src_user$
mitre_attack_id:
- T1134.005
- T1134
nist:
- DE.CM
observable:
- name: src_user
type: User
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- SidHistory
- TargetSid
- TargetDomainName
- user
- src_user
- Logon_ID
risk_score: 80
security_domain: endpoint
@@ -0,0 +1,69 @@
name: Windows AD Domain Controller Promotion
id: e633a0ef-2a6e-4ed7-b925-5ff999e5d1f0
version: 1
date: '2023-01-26'
author: Dean Luxton
type: TTP
datamodel: []
description: This analytic identifies a genuine DC promotion event. Identifying when a computer assigns itself the
necessary SPNs to function as a domain controller. Note these events are triggered on the existing domain controllers, not the newly
joined domain controller. This detection will serve to identify rogue DCs added to the network. There are 2x detections within this analytic story
which identify DCShadow attacks, if you do not currently possess the logging for these detections, remove the where clause within this
detection to identify DCShadow activity.
search: "`wineventlog_security` EventCode=4742 ServicePrincipalNames IN (\"*E3514235-4B06-11D1-AB04-00C04FC2DCD2/*\"\
, \"*GC/*\") \n| stats min(_time) as _time latest(ServicePrincipalNames) as ServicePrincipalNames,\
\ values(signature) as signature, values(src_user) as src_user, values(user) as\
\ user by Logon_ID, dvc\n| where src_user=user\n| rename Logon_ID as TargetLogonId,\
\ user as dest\n| appendpipe [| map search=\"search `wineventlog_security` EventCode=4624\
\ TargetLogonId=$TargetLogonId$\" | fields - dest, dvc, signature]\n| stats min(_time)\
\ as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain,\
\ values(user) as user, values(status) as status, values(src_category) as src_category,\
\ values(src_ip) as src_ip values(ServicePrincipalNames) as ServicePrincipalNames\
\ values(signature) as signature values(dest) as dest values(dvc) as dvc by TargetLogonId\n\
| eval dest=trim(dest,\"$\") | `windows_ad_domain_controller_promotion_filter`"
how_to_implement: To successfully implement this search, you need to be ingesting eventcode
`4742`. The Advanced Security Audit policy setting `Audit Computer Account Management`
within `Account Management` needs to be enabled.
known_false_positives: None.
references:
- https://attack.mitre.org/techniques/T1207/
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
confidence: 100
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/dc_promo/windows-security-xml.log
impact: 80
kill_chain_phases:
- Actions on Objectives
message: AD Domain Controller Promotion Event Detected for $dest$
mitre_attack_id:
- T1207
nist:
- DE.CM
observable:
- name: dest
type: Hostname
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ServicePrincipalNames
- src_user
- user
- Logon_ID
- dvc
risk_score: 80
security_domain: endpoint
@@ -0,0 +1,75 @@
name: Windows AD DSRM Account Changes
id: 08cb291e-ea77-48e8-a95a-0799319bf056
version: 1
date: '2022-09-08'
author: Dean Luxton
type: TTP
datamodel:
- Endpoint
description: Aside from being used to promote genuine domain controllers, the DSRM (Directory Services Restore Mode)
account can be used to persist within a Domain. A DC can be configured to allow the DSRM account to logon & be
used in the same way as a local administrator account. This detection is looking for alterations to the behaviour
of the account via registry.
search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Endpoint.Registry
where Registry.registry_path= "*\\System\\CurrentControlSet\\Control\\Lsa\\DSRMAdminLogonBehavior"
Registry.registry_value_data IN ("*1","*2") by Registry.action Registry.registry_path
Registry.registry_value_data Registry.registry_value_type Registry.process_guid
| `drop_dm_object_name(Registry)`
| join type=outer process_guid [| tstats `security_content_summariesonly` count
FROM datamodel=Endpoint.Processes by Processes.user Processes.process_name Processes.process
Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid
| `drop_dm_object_name(Processes)`]
| table _time action dest user parent_process_name parent_process process_name process
process_guid registry_path registry_value_data registry_value_type | `windows_ad_dsrm_account_changes_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
used for this search is typically generated via logs that report reads and writes
to the registry.
known_false_positives: Disaster recovery events.
references:
- https://adsecurity.org/?p=1714
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
- Windows Registry Abuse
- Windows Persistence Techniques
asset_type: Endpoint
cis20:
- CIS 6
confidence: 100
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: DSRM Account Changes Initiated on $dest$ by $user$
mitre_attack_id:
- T1098
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_value_data
- Registry.registry_path
- Registry.dest
- Registry.user
risk_score: 100
security_domain: endpoint
@@ -0,0 +1,65 @@
name: Windows AD DSRM Password Reset
id: d1ab841c-36a6-46cf-b50f-b2b04b31182a
version: 1
date: '2022-09-08'
author: Dean Luxton
type: TTP
datamodel:
- Change
description: Aside from being used to promote genuine domain controllers, the DSRM (Directory Services Restore Mode)
account can be used to persist within a Domain. A DC can be configured to allow the DSRM account to logon & be
used in the same way as a local administrator account. This detection is looking for any password reset attempts against that account.
search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Change
where All_Changes.result_id="4794" AND All_Changes.result="An attempt was made to
set the Directory Services Restore Mode administrator password" by All_Changes.action,
All_Changes.dest, All_Changes.src, All_Changes.user
| `drop_dm_object_name(All_Changes)` | `windows_ad_dsrm_password_reset_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting eventcode
`4794` and have the Advanced Security Audit policy
`Audit User Account Management` within `Account Management` enabled.
known_false_positives: Resetting the DSRM password for legitamate reasons, i.e. forgot the password. Disaster recovery. Deploying AD backdoor deliberately.
references:
- https://adsecurity.org/?p=1714
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 6
confidence: 100
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: DSRM Account Password was reset on $dest$ by $user$
mitre_attack_id:
- T1098
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.result_id
- All_Changes.result
- All_Changes.action
- All_Changes.dest
- All_Changes.src
- All_Changes.user
risk_score: 100
security_domain: endpoint
@@ -0,0 +1,84 @@
name: Windows AD Replication Request Initiated by User Account
id: 51307514-1236-49f6-8686-d46d93cc2821
version: 1
date: '2022-09-08'
author: Dean Luxton
type: TTP
datamodel: []
description: This alert was written to detect activity associated with the DCSync attack.
When a domain controller receives a replication request, the user account permissions are validated, however no checks are performed to validate the request was initiated by a Domain Controller.
Once an attacker gains control of an account with the necessary privileges, they can request password hashes for any or all users within the domain.
This alert detects when a user account creates a handle to domainDNS with the necessary replication permissions.
search: '`wineventlog_security` EventCode=4662 ObjectType IN ("%{19195a5b-6da0-11d0-afd3-00c04fd930c9}", "domainDNS") AND Properties IN ("*Replicating Directory Changes All*", "*{1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}*", "*{9923a32a-3607-11d2-b9be-0000f87a36b2}*","*{1131f6ac-9c07-11d1-f79f-00c04fc2dcd2}*") AND AccessMask="0x100" AND NOT (SubjectUserSid="NT AUT*" OR SubjectUserSid="S-1-5-18" OR SubjectDomainName="Window Manager" OR SubjectUserName="*$")
| stats min(_time) as _time, count by SubjectDomainName, SubjectUserName, Computer, Logon_ID, ObjectName, ObjectServer, ObjectType, OperationType, status
| rename SubjectDomainName as Target_Domain, SubjectUserName as user, Logon_ID as TargetLogonId, _time as attack_time
| appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"]
| table attack_time, AuthenticationPackageName, LogonProcessName, LogonType, TargetUserSid, Target_Domain, user, Computer, TargetLogonId, status, src_ip, src_category, ObjectName, ObjectServer, ObjectType, OperationType
| stats min(attack_time) as _time values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) as status, values(src_category) as src_category, values(src_ip) as src_ip by TargetLogonId
| `windows_ad_replication_request_initiated_by_user_account_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting eventcode `4662`.
The Advanced Security Audit policy settings `Audit Directory Services Access`
within `DS Access` needs to be enabled, as well as the following SACLs applied to the domain root
and all descendant objects. The principals `everybody`, `Domain Computers`, and `Domain Controllers`
auditing the permissions `Replicating Directory Changes`, `Replicating Directory Changes All`, and
`Replicating Directory Changes In Filtered Set`
known_false_positives: Azure AD Connect syncing operations.
references:
- https://adsecurity.org/?p=1729
- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
- Credential Dumping
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
confidence: 100
context:
- Source:Endpoint
- Source:AD
- Stage:Credential Access
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: Windows Active Directory Replication Request Initiated by User Account $user$ at $src_ip$
mitre_attack_id:
- T1003.006
- T1003
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: src_ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ObjectType
- Properties
- AccessMask
- SubjectDomainName
- SubjectUserName
- SubjectUserSid
- Computer
- Logon_ID
- ObjectName
- ObjectServer
- ObjectType
- OperationType
- status
risk_score: 100
security_domain: endpoint
@@ -0,0 +1,101 @@
name: Windows AD Replication Request Initiated from Unsanctioned Location
id: 50998483-bb15-457b-a870-965080d9e3d3
version: 1
date: '2022-11-17'
author: Dean Luxton
type: TTP
datamodel: []
description: This alert was written to detect activity associated with the DCSync attack performed by computer accounts.
When a domain controller receives a replication request, the account permissions are validated, however no checks are performed to validate the request was initiated by a Domain Controller.
Once an attacker gains control of an account with the necessary privileges, they can request password hashes for any or all users within the domain.
This alert detects when a computer account account creates a handle to domainDNS with the necessary replication permissions. These requests are then filtered to exclude where the events originate
from a known domain controller IP address.
search: '`wineventlog_security` EventCode=4662 ObjectType IN ("%{19195a5b-6da0-11d0-afd3-00c04fd930c9}",
"domainDNS") AND Properties IN ("*Replicating Directory Changes All*", "*{1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}*",
"*{9923a32a-3607-11d2-b9be-0000f87a36b2}*","*{1131f6ac-9c07-11d1-f79f-00c04fc2dcd2}*")
AND AccessMask="0x100" AND (SubjectUserSid="NT AUT*" OR SubjectUserSid="S-1-5-18" OR SubjectDomainName="Window Manager" OR SubjectUserName="*$")
| stats min(_time) as attack_time, count by SubjectDomainName, SubjectUserName,
Computer, Logon_ID, ObjectName, ObjectServer, ObjectType, OperationType, status
| rename SubjectDomainName as Target_Domain, SubjectUserName as user, Logon_ID as
TargetLogonId
| appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"]
| table attack_time, AuthenticationPackageName, LogonProcessName, LogonType, TargetUserSid,
Target_Domain, user, Computer, TargetLogonId, status, src_ip, src_category, ObjectName,
ObjectServer, ObjectType, OperationType
| stats min(attack_time) as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain)
as Target_Domain, values(user) as user, values(Computer) as Computer, values(status)
as status, values(src_category) as src_category, values(src_ip) as src_ip by TargetLogonId
| search NOT src_category="domain_controller" | `windows_ad_replication_request_initiated_from_unsanctioned_location_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting eventcode `4662`.
The Advanced Security Audit policy settings `Audit Directory Services Access`
within `DS Access` needs to be enabled, as well as the following SACLs applied to the domain root
and all descendant objects. The principals `everybody`, `Domain Computers`, and `Domain Controllers`
auditing the permissions `Replicating Directory Changes`, `Replicating Directory Changes All`, and
`Replicating Directory Changes In Filtered Set`
Assets and Identities will also need to be configured, with the category of domain_controller added for domain controllers.
known_false_positives: Genuine DC promotion may trigger this alert.
references:
- https://adsecurity.org/?p=1729
- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
- Credential Dumping
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
confidence: 100
context:
- Source:Endpoint
- Source:AD
- Stage:Credential Access
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: Windows Active Directory Replication Request Initiated from Unsanctioned Location $src_ip$ by $user$
mitre_attack_id:
- T1003.006
- T1003
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: src_ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ObjectType
- Properties
- AccessMask
- SubjectDomainName
- SubjectUserName
- SubjectUserSid
- Computer
- Logon_ID
- ObjectName
- ObjectServer
- ObjectType
- OperationType
- status
risk_score: 100
security_domain: endpoint
@@ -0,0 +1,78 @@
name: Windows AD Same Domain SID History Addition
id: 5fde0b7c-df7a-40b1-9b3a-294c00f0289d
version: 2
date: '2022-09-09'
author: Dean Luxton
type: TTP
datamodel: []
description: The following analytic looks for changes to the sIDHistory AD attribute of user or computer objects which exist within the same domain.
The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access
continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries to stealthily grant access to a backdoor account within the same domain.
This analytic was written to pick up on activity via Mimikatz sid::patch. Please note there are additional avenues to abuse SID history such as DCShadow & Golden / Diamond tickets which won't be detected using these event codes.
search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory
IN ("%%1793", -)
| rex field=SidHistory "(^%{|^)(?P<SidHistoryMatch>.*)(\-|\\\)"
| rex field=TargetSid "^(?P<TargetSidmatch>.*)(\-|\\\)"
| where SidHistoryMatch=TargetSidmatch OR SidHistoryMatch=TargetDomainName
| rename TargetSid as userSid, TargetDomainName as userDomainName
| table _time action status host user userSid userDomainName SidHistory Logon_ID src_user
| `windows_ad_same_domain_sid_history_addition_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting eventcodes
`4738` and `4742`. The Advanced Security Audit policy settings
`Audit User Account Management` and `Audit Computer Account Management`
within `Account Management` all need to be enabled. SID resolution is not required..
known_false_positives: Unknown
references:
- https://adsecurity.org/?p=1772
- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN
- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute
- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
- Windows Persistence Techniques
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
- CIS 16
confidence: 100
context:
- Source:AD
- Stage:Persistence
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: Active Directory SID History Attribute was added to $user$ by $src_user$
mitre_attack_id:
- T1134.005
- T1134
nist:
- DE.CM
observable:
- name: src_user
type: User
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- SidHistory
- TargetSid
- TargetDomainName
- user
- src_user
- Logon_ID
risk_score: 100
security_domain: endpoint
@@ -0,0 +1,69 @@
name: Windows AD ServicePrincipalName Added To Domain Account
id: 8a1259cb-0ea7-409c-8bfe-74bad89259f9
version: 1
date: '2022-11-17'
author: Mauricio Velazco, Splunk
type: TTP
datamodel: []
description: The following analytic identifies the addition of a Service Principal Name to a domain account. While this event may be part of a legitimate action part of certain administrative operations,
it may also be evidence of a persistence attack. Domain accounts with Servce Principal Names are vulnerable to a technique called Kerberoasting that enables attackers to potentially obtain the cleartext password
of the account by performing offline cracking. An adversary who has obtained privileged access to a domain environment may add an SPN to a privileged account to then leverage the Kerberoasting technique and attempt
to obtain its clertext password.
search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName OperationType="%%14674"
| stats values(ObjectDN) by _time, Computer, SubjectUserName, AttributeValue
| `windows_ad_serviceprincipalname_added_to_domain_account_filter`'
how_to_implement: To successfully implement this search, you ned to be ingesting eventcode
`5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes`
within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications.
known_false_positives: A Service Principal Name should only be added to an account when an application requires it. While infrequent, this detection may trigger on
legitimate actions. Filter as needed.
references:
- https://adsecurity.org/?p=3466
- https://www.thehacker.recipes/ad/movement/dacl/targeted-kerberoasting
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136
- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting
tags:
analytic_story:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log
asset_type: endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 50
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log
impact: 60
kill_chain_phases:
- Installation
- Actions on Objectives
message: A Servince Principal Name for $ObjectDN$ was set by $SubjectUserName$
mitre_attack_id:
- T1098
nist:
- DE.CM
observable:
- name: SubjectUserName
type: User
role:
- Attacker
- name: ObjectDN
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ObjectDN
- signature
- SubjectUserName
- Computer
risk_score: 30
security_domain: endpoint
@@ -0,0 +1,71 @@
name: Windows AD Short Lived Domain Account ServicePrincipalName
id: b681977c-d90c-4efc-81a5-c58f945fb541
version: 1
date: '2022-11-18'
author: Mauricio Velazco, Splunk
type: TTP
datamodel: []
description: The following analytic identifies the addition of a Service Principal Name to a domain account that is quickly deleted within 5 minutes or less. While this event may be part of a legitimate action part of certain administrative operations,
it may also be evidence of a persistence attack. Domain accounts with Service Principal Names are vulnerable to a technique called Kerberoasting that enables attackers to potentially obtain the cleartext password
of the account by performing offline cracking. An adversary who has obtained privileged access to a domain environment may add an SPN to a privileged account to then leverage the Kerberoasting technique and attempt
to obtain its clertext password. To clean things up, the adversary may delete the SPN which will trigger this detection.
search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName
| transaction ObjectDN AttributeValue startswith=(EventCode=5136 OperationType="%%14674") endswith=(EventCode=5136 OperationType="%%14675")
| eval short_lived=case((duration<300),"TRUE")
| search short_lived = TRUE
| `windows_ad_short_lived_domain_account_serviceprincipalname_filter`'
how_to_implement: To successfully implement this search, you ned to be ingesting eventcode
`5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes`
within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications.
known_false_positives: A Service Principal Name should only be added to an account when an application requires it. Adding an SPN and quickly deleting it
is less common but may be part of legitimate action. Filter as needed.
references:
- https://adsecurity.org/?p=3466
- https://www.thehacker.recipes/ad/movement/dacl/targeted-kerberoasting
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136
- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 80
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/short_lived_service_principal_name/windows-security.log
impact: 50
kill_chain_phases:
- Installation
- Actions on Objectives
message: A Servince Principal Name for $ObjectDN$ was set and shortly deleted
mitre_attack_id:
- T1098
nist:
- DE.CM
observable:
- name: SubjectUserName
type: User
role:
- Attacker
- name: ObjectDN
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ObjectDN
- signature
- SubjectUserName
- Computer
risk_score: 40
security_domain: endpoint
@@ -0,0 +1,78 @@
name: Windows AD Short Lived Domain Controller SPN Attribute
id: 57e27f27-369c-4df8-af08-e8c7ee8373d4
version: 2
date: '2022-09-02'
author: Dean Luxton
type: TTP
datamodel: []
description: The following analytic identifies when either a global catalog SPN or a DRS RPC SPN are temporarily added to an Active Directory computer object, both of which can be evidence of a DCShadow attack.
DCShadow allows an attacker who has obtained privileged access to register a rogue Domain Controller (DC). Once registered, the rogue DC may be able to inject
and replicate changes into the AD infrastructure for any domain object, including credentials and keys. This technique was initially released in 2018 by security researchers Benjamin Delpy and Vincent Le Toux.
No event logs are written for changes to AD attributes, allowing for stealthy backdoors to be implanted in the domain, or metadata such as timestamps overwritten to cover tracks.
search: '`wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName (AttributeValue="GC/*" OR AttributeValue="E3514235-4B06-11D1-AB04-00C04FC2DCD2/*")
| stats min(_time) as _time range(_time) as duration values(OperationType) as OperationType values(src_nt_domain) as src_nt_domain values(src_user) as src_user values(Computer) as Computer, values(ObjectDN) as ObjectDN by Logon_ID
| eval short_lived=case((duration<30),"TRUE")
| where short_lived="TRUE" AND mvcount(OperationType)>1
| replace "%%14674" with "Value Added", "%%14675" with "Value Deleted" in OperationType
| rename Logon_ID as TargetLogonId
| appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"]
| stats min(_time) as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) as status, values(src_category) as src_category, values(src_ip) as src_ip values(ObjectDN) as ObjectDN values(OperationType) as OperationType by TargetLogonId
| `windows_ad_short_lived_domain_controller_spn_attribute_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting eventcode
`5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes`
within `DS Access` needs to be enabled, alongside a SACL for `everybody` to
`Write All Properties` applied to the domain root and all descendant objects.
known_false_positives: None.
references:
- https://www.dcshadow.com/
- https://blog.netwrix.com/2022/09/28/dcshadow_attack/
- https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2
- https://attack.mitre.org/techniques/T1207/
- https://blog.alsid.eu/dcshadow-explained-4510f52fc19d
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
confidence: 100
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/mimikatz/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: Short Lived Domain Controller SPN AD Attribute Triggered by $user$ from $src_ip$
mitre_attack_id:
- T1207
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: src_ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- AttributeLDAPDisplayName
- AttributeValue
- src_nt_domain
- src_user
- Computer
- ObjectDN
- Logon_ID
- signature
risk_score: 100
security_domain: endpoint
@@ -0,0 +1,77 @@
name: Windows AD Short Lived Server Object
id: 193769d3-1e33-43a9-970e-ad4a88256cdb
version: 1
date: '2022-10-17'
author: Mauricio Velazco, Splunk
type: TTP
datamodel: []
description: 'The following analytic identifies a change in an Active Directory environment that could represent evidence of the DCShadow attack.
DCShadow allows an attacker who has obtained privileged access to register a rogue Domain Controller (DC). Once registered, the rogue DC may be able to inject
and replicate changes in the AD infrastructure for any domain object, including credentials and keys. This technique was initially released in 2018 by security
researchers Benjamin Delpy and Vincent Le Toux. Specifically, the detection will trigger when a possible rogue Domain Controller
computer object is created and quickly deleted within 30 seconds or less in an Active Directory domain. This behavior was identfied by simulating the DCShadow attack with
Mimikatz.'
search: ' `wineventlog_security` EventCode=5137 OR EventCode=5141 ObjectDN="*CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration*"
| transaction ObjectDN startswith=(EventCode=5137) endswith=(EventCode=5141)
| eval short_lived=case((duration<30),"TRUE")
| search short_lived = TRUE
| stats values(ObjectDN) values(signature) values(EventCode) by _time, Computer, SubjectUserName
| `windows_ad_short_lived_server_object_filter`'
how_to_implement: To successfully implement this search, you ned to be ingesting Event codes
`5137` and `5141`. The Advanced Security Audit policy setting `Audit Directory Services Changes`
within `DS Access` needs to be enabled. For these event codes to be generated, specific SACLs are required.
known_false_positives: Creating and deleting a server object within 30 seconds or less is unusual but not impossible in a production environment. Filter as needed.
references:
- https://www.dcshadow.com/
- https://attack.mitre.org/techniques/T1207/
- https://stealthbits.com/blog/detecting-dcshadow-with-event-logs/
- https://pentestlab.blog/2018/04/16/dcshadow/
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5137
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5141
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
- Stage:Privilege Escalation
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/short_lived_server_object/windows-security.log
impact: 80
kill_chain_phases:
- Installation
- Actions on Objectives
message: Potential DCShadow Attack Detected on $Computer$
mitre_attack_id:
- T1207
nist:
- DE.CM
observable:
- name: SubjectUserName
type: User
role:
- Attacker
- name: Computer
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ObjectDN
- signature
- SubjectUserName
- Computer
risk_score: 64
security_domain: endpoint
@@ -0,0 +1,66 @@
name: Windows AD SID History Attribute Modified
id: 1155e47d-307f-4247-beab-71071e3a458c
version: 1
date: '2022-11-16'
author: Mauricio Velazco, Splunk
type: TTP
datamodel: []
description: The following analytic leverages event code `5136` to identify a modification of the SID History AD attribute.
The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access
continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries to stealthily grant access to a backdoor account within the same domain.
search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=sIDHistory OperationType="%%14674"
| stats values(ObjectDN) by _time, Computer, SubjectUserName, AttributeValue
| `windows_ad_sid_history_attribute_modified_filter`'
how_to_implement: To successfully implement this search, you ned to be ingesting eventcode
`5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes`
within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications.
known_false_positives: Domain mergers and migrations may generate large volumes of false positives for this analytic.
references:
- https://adsecurity.org/?p=1772
- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN
- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute
- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 70
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/sid_history2/windows-security.log
impact: 80
kill_chain_phases:
- Installation
- Actions on Objectives
message: SID History AD attribute modified by $SubjectUserName$ for $ObjectDN$
mitre_attack_id:
- T1134
- T1134.005
nist:
- DE.CM
observable:
- name: SubjectUserName
type: User
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- AttributeLDAPDisplayName
- OperationType=
- ObjectDN
- Computer
- SubjectUserName
- AttributeValue
risk_score: 56
security_domain: endpoint
@@ -1,18 +1,14 @@
name: Windows Disable Windows Group Policy Features Through Registry
id: 63a449ae-9f04-11ec-945e-acde48001122
version: 2
version: 3
date: '2022-11-14'
author: Steven Dick, Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic is to detect a suspicious registry modification to disable
windows features. These techniques are seen in several ransomware malware to impair
the compromised host to make it hard for analyst to mitigate or response from the
attack. Disabling these known features make the analysis and forensic response more
hard. Disabling these feature is not so common but can still be implemented by the
administrator for security purposes. In this scenario filters for users that are
allowed doing this is needed.
description: The following analytic detects a suspicious registry modification used to disable
windows features. This technique has been identified in several ransomware malware families to impair
the compromised host and make it harder for analysts to mitigate or respond to an attack.
search: '| tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime FROM datamodel=Endpoint.Processes BY _time span=1h Processes.user Processes.process_id Processes.process_name Processes.process Processes.process_path Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid
| `drop_dm_object_name(Processes)`
| join process_guid [
@@ -27,7 +23,8 @@ how_to_implement: To successfully implement this search, you need to be ingestin
logs with the registry value name, registry path, and registry value data from your
endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical
Sysmon TA. https://splunkbase.splunk.com/app/5709
known_false_positives: unknown
known_false_positives: Disabling these features for legitimate purposes is not a common use case but can still be implemented by the
administrators. Filter as needed.
references:
- https://hybrid-analysis.com/sample/ef1c427394c205580576d18ba68d5911089c7da0386f19d1ca126929d3e671ab?environmentId=120&lang=en
- https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Krotten-N/detailed-analysis
@@ -37,6 +34,7 @@ tags:
- Ransomware
- Windows Defense Evasion Tactics
- Windows Registry Abuse
- Sneaky Active Directory Persistence Tricks
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log
kill_chain_phases:
@@ -1,15 +1,15 @@
name: Windows Driver Load Non-Standard Path
id: 9216ef3d-066a-4958-8f27-c84589465e62
version: 1
date: '2022-04-04'
version: 2
date: '2023-02-24'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic uses Windows EventCode 7045 to identify new Kernel Mode Drivers being loaded in Windows from a non-standard path.
description: The following analytic uses Windows XML EventCode 7045 to identify new Kernel Mode Drivers being loaded in Windows from a non-standard path.
Note that, adversaries may move malicious or vulnerable drivers into these paths and load up. The idea is that this analytic provides visibility into drivers loading in non-standard file paths.
search: '`wineventlog_system` EventCode=7045 Service_Type="kernel mode driver" NOT (Service_File_Name IN ("*\\Windows\\*", "*\\Program File*", "*\\systemroot\\*","%SystemRoot%*", "system32\*"))
| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Service_File_Name Service_Name Service_Start_Type Service_Type
search: '`wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" NOT (ImagePath IN ("*\\Windows\\*", "*\\Program File*", "*\\systemroot\\*","%SystemRoot%*", "system32\*"))
| stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ImagePath ServiceName ServiceType
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_driver_load_non_standard_path_filter`'
@@ -34,13 +34,14 @@ tags:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/7045_kerneldrivers.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/xml7045_windows-system.log
impact: 60
kill_chain_phases:
- Installation
message: A kernel mode driver was loaded from a non-standard path on $ComputerName$.
mitre_attack_id:
- T1014
- T1068
nist:
- DE.CM
observable:
@@ -53,11 +54,11 @@ tags:
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- ComputerName
- _time
- Computer
- EventCode
- Service_File_Name
- Service_Name
- Service_Start_Type
- Service_Type
- ImagePath
- ServiceName
- ServiceType
risk_score: 36
security_domain: endpoint
@@ -6,7 +6,7 @@ author: Michael Haag, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies hardcoded extensions related to the Crypo module within Mimikatz. Moving certificates or downloading them is not malicious, however with Mimikatz having hardcoded names it helps to identify potential usage of certificates being exported.
description: The following analytic identifies hardcoded extensions related to the Crypto module within Mimikatz. Moving certificates or downloading them is not malicious, however with Mimikatz having hardcoded names it helps to identify potential usage of certificates being exported.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.keyx.rsa.pvk","*sign.rsa.pvk","*sign.dsa.pvk","*dsa.ec.p8k","*dh.ec.p8k", "*.pfx", "*.der") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Filesystem)` | `windows_mimikatz_crypto_export_file_extensions_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
@@ -0,0 +1,74 @@
name: Windows Process Injection into Notepad
id: b8340d0f-ba48-4391-bea7-9e793c5aae36
version: 1
date: '2023-02-22'
author: Michael Haag, Splunk
type: Anomaly
datamodel: []
description: The following analytic utilizes Sysmon to identify process injection into Notepad.exe, based on GrantedAccess requests - 0x40 and 0x1fffff. This particular behavior is attributed to the defaults of the SliverC2 framework by BishopFox.
By default, the analytic filters out any SourceImage paths of System32, Syswow64 and program files. Add more as needed, or remove and monitor what is consistently injecting into notepad.exe.
This particular behavior will occur from a source image that is the initial payload dropped.
search: '`sysmon` EventCode=10 TargetImage IN (*\\notepad.exe) NOT (SourceImage IN ("*\\system32\\*","*\\syswow64\\*","*\\Program Files\\*")) GrantedAccess IN ("0x40","0x1fffff") | stats count min(_time) as firstTime max(_time) as lastTime by dest SourceImage TargetImage GrantedAccess CallTrace
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_process_injection_into_notepad_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: False positives may be present based on SourceImage paths. If removing the paths is important, realize svchost and many native binaries inject into notepad consistently. Restrict or tune as needed.
references:
- https://dominicbreuker.com/post/learning_sliver_c2_08_implant_basics/
- https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors
tags:
analytic_story:
- BishopFox Sliver Adversary Emulation Framework
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/T1055_windows-sysmon.log
impact: 40
kill_chain_phases:
- Exploitation
message: An instance of $SourceImage$ injecting into $TargetImage$ was identified on endpoint $dest$.
mitre_attack_id:
- T1055
- T1055.002
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: SourceImage
type: Process
role:
- Parent Process
- name: TargetImage
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- dest
- SourceImage
- TargetImage
- GrantedAccess
- CallTrace
risk_score: 32
security_domain: endpoint
@@ -32,6 +32,7 @@ tags:
analytic_story:
- Windows Post-Exploitation
- Prestige Ransomware
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 3
@@ -0,0 +1,55 @@
name: Windows Service Create SliverC2
id: 89dad3ee-57ec-43dc-9044-131c4edd663f
version: 1
date: '2023-03-03'
author: Michael Haag, Splunk
type: TTP
datamodel: []
description: When an adversary utilizes SliverC2 to laterally move with the Psexec module, it will create a service with the name and description of "Sliver" and "Sliver Implant". Note that these may be easily changed and are specific to only SliverC2.
We have also created the same regex as Microsoft has outlined to attempt to capture the suspicious service path (regex101 reference).
search: '`wineventlog_system` EventCode=7045 ServiceName="sliver"
| stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ImagePath ServiceName ServiceType
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `windows_service_create_sliverc2_filter`'
how_to_implement: To implement this analytic, the Windows EventCode 7045 will need to be logged from the System Event log. The Windows TA for Splunk is also recommended.
known_false_positives: False positives should be limited, but if another service out there is named Sliver, filtering may be needed.
references:
- https://github.com/BishopFox/sliver/blob/71f94928bf36c1557ea5fbeffa161b71116f56b2/client/command/exec/psexec.go#LL61C5-L61C16
- https://www.microsoft.com/en-us/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/
- https://regex101.com/r/DWkkXm/1
tags:
analytic_story:
- BishopFox Sliver Adversary Emulation Framework
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 100
context:
- Source:Endpoint
- Stage:Lateral Movement
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/sliver_windows-system.log
impact: 90
kill_chain_phases:
- Installation
message: A user mode service was created on $ComputerName$ related to SliverC2.
mitre_attack_id:
- T1569
- T1569.002
nist:
- DE.CM
observable:
- name: ComputerName
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- UPDATE
risk_score: 90
security_domain: endpoint
@@ -0,0 +1,64 @@
name: Windows AD Domain Controller Audit Policy Disabled
id: fc3ccef1-60a4-4239-bd66-b279511b4d14
version: 1
date: '2023-01-26'
author: Dean Luxton
type: TTP
datamodel: []
description: This analytic looks for audit policies being disabled on a domain controller.
search: '`wineventlog_security` EventCode=4719 (AuditPolicyChanges IN ("%%8448","%%8450","%%8448,
%%8450") OR Changes IN ("Failure removed","Success removed","Success removed, Failure
removed")) dest_category="domain_controller"
| replace "%%8448" with "Success removed", "%%8450" with "Failure removed", "%%8448,
%%8450" with "Success removed, Failure removed" in AuditPolicyChanges
| eval AuditPolicyChanges=coalesce(AuditPolicyChanges,Changes), SubcategoryGuid=coalesce(SubcategoryGuid,Subcategory_GUID)
| stats min(_time) as _time values(host) as dest by AuditPolicyChanges SubcategoryGuid
| lookup advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory
| `windows_ad_domain_controller_audit_policy_disabled_filter`'
how_to_implement: Ensure you are ingesting EventCode `4719` from your domain controllers, the category domain_controller exists
in assets and identities, and that assets and identities is enabled. If A&I is not configured, you will need to manually filter the results
within the base search.
known_false_positives: Unknown
references:
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4719
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
confidence: 60
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_gpo/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: GPO $SubCategory$ of $Category$ was disabled on $dest$
mitre_attack_id:
- T1562.001
nist:
- DE.CM
observable:
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- AuditPolicyChanges
- SubcategoryGuid
risk_score: 60
security_domain: endpoint
@@ -0,0 +1,89 @@
name: Windows AD Domain Replication ACL Addition
id: 8c372853-f459-4995-afdc-280c114d33ab
version: 1
date: '2022-11-18'
author: Dean Luxton
type: TTP
datamodel: []
description: This analytic detects the addition of the permissions necessary to perform a DCSync attack.
In order to replicate AD objects, the initiating user or computer must have the following permissions on the domain.
- DS-Replication-Get-Changes
- DS-Replication-Get-Changes-All
Certain Sync operations may require the additional permission of DS-Replication-Get-Changes-In-Filtered-Set.
By default, adding DCSync permissions via the Powerview Add-ObjectACL operation adds all 3. This alert identifies where this trifecta has been met, and also where just the base level requirements have been met.
search: "`wineventlog_security` (EventCode=5136) AttributeLDAPDisplayName=\"ntSecurityDescriptor\"\
\ \"1131f6ad-9c07-11d1-f79f-00c04fc2dcd2\" OR \"1131f6aa-9c07-11d1-f79f-00c04fc2dcd2\"\
\ OR \"89e95b76-444d-4c62-991a-0facbeda640c\" \n| where AttributeValue like \"%1131f6ad-9c07-11d1-f79f-00c04fc2dcd2%\"\
\ AND AttributeValue like \"%1131f6aa-9c07-11d1-f79f-00c04fc2dcd2%\" AND AttributeValue\
\ like \"%89e95b76-444d-4c62-991a-0facbeda640c%\" \n| search NOT ObjectClass IN\
\ (dnsNode,dnsZoneScope,dnsZone)\n| rex field=AttributeValue max_match=10000 \"\
OA;;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;(?P<DSRGetChanges_user_sid>S-1-[0-59]-\\\
d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| rex field=AttributeValue\
\ max_match=10000 \"OA;;CR;1131f6ad-9c07-11d1-f79f-00c04fc2dcd2;;(?P<DSRGetChangesAll_user_sid>S-1-[0-59]-\\\
d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| rex field=AttributeValue\
\ max_match=10000 \"OA;;CR;89e95b76-444d-4c62-991a-0facbeda640c;;(?P<DSRGetChangesFiltered_user_sid>S-1-[0-59]-\\\
d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| table _time dest src_user DSRGetChanges_user_sid\
\ DSRGetChangesAll_user_sid DSRGetChangesFiltered_user_sid\n| mvexpand DSRGetChanges_user_sid\n\
| eval minDCSyncPermissions=if(DSRGetChanges_user_sid=DSRGetChangesAll_user_sid,\"\
true\",\"false\"), fullSet=if(DSRGetChanges_user_sid=DSRGetChangesAll_user_sid AND\
\ DSRGetChanges_user_sid=DSRGetChangesFiltered_user_sid,\"true\",\"false\")\n| where\
\ minDCSyncPermissions=\"true\"\n| lookup identity_lookup_expanded objectSid as\
\ DSRGetChanges_user_sid OUTPUT sAMAccountName as user\n| rename DSRGetChanges_user_sid\
\ as userSid\n| stats min(_time) as _time values(user) as user by dest src_user userSid minDCSyncPermissions fullSet|\
\ `windows_ad_domain_replication_acl_addition_filter`"
how_to_implement: To successfully implement this search, you need to be ingesting the eventcode 5136. The Advanced Security Audit policy setting
`Audit Directory Services Changes` within `DS Access` needs to be enabled, alongside a SACL for `everybody` to `Write All Properties`
applied to the domain root and all descendant objects. Once the necessary logging has been enabled, enumerate the domain policy to verify if existing
accounts with access need to be whitelisted, or revoked. Assets and Identities is also leveraged to automatically translate the objectSid into username.
Ensure your identities lookup is configured with the sAMAccountName and objectSid of all AD user and computer objects.
known_false_positives: When there is a change to nTSecurityDescriptor, Windows logs the entire ACL with the newly added components.
If existing accounts are present with this permission, they will raise an alert each time the nTSecurityDescriptor is updated unless whitelisted.
references:
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/1522b774-6464-41a3-87a5-1e5633c3fbbb
- https://github.com/SigmaHQ/sigma/blob/29a5c62784faf986dc03952ae3e90e3df3294284/rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 6
confidence: 80
context:
- Source:Endpoint
- Stage:Persistence
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/aclmodification/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: $src_user$ has granted $user$ permission to replicate AD objects
mitre_attack_id:
- T1484
nist:
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: src_user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- dest
- src_user
- AttributeLDAPDisplayName
- AttributeValue
- ObjectClass
risk_score: 80
security_domain: endpoint
@@ -0,0 +1,77 @@
name: Windows AD Privileged Account SID History Addition
id: 6b521149-b91c-43aa-ba97-c2cac59ec830
version: 1
date: '2022-09-12'
author: Dean Luxton
type: TTP
datamodel: []
description: This detection identifies when the SID of a privileged user is added to
the SID History attribute of another user. Useful for tracking SID history abuse
across multiple domains. This detection leverages the Asset and Identities
framework. See the implementation section for further details on configuration.
search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory IN ("%%1793", -)
| rex field=SidHistory "(^%{|^)(?P<SidHistory>.*?)(}$|$)"
| eval category="privileged"
| lookup identity_lookup_expanded category, identity as SidHistory OUTPUT identity_tag as match
| where isnotnull(match)
| rename TargetSid as userSid
| table _time action status host user userSid SidHistory Logon_ID src_user
| `windows_active_directory_privileged_account_sid_history_addition_filter`'
how_to_implement: Ensure you have objectSid and the Down Level Logon Name `DOMAIN\sAMACountName`
added to the identity field of your Asset and Identities lookup, along with the
category of privileged for the applicable users. Ensure you are
ingesting eventcodes 4742 and 4738. Two advanced audit policies
`Audit User Account Management` and `Audit Computer Account Management` under
`Account Management` are required to generate these event codes.
known_false_positives: Migration of privileged accounts.
references:
- https://adsecurity.org/?p=1772
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
- CIS 16
confidence: 90
context:
- Source:Endpoint
- Source:AD
- Stage:Defense Evasion
- Stage:Privilege Escalation
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: A Privileged User Account SID History Attribute was added to $user$ by $src_user$
mitre_attack_id:
- T1134.005
- T1134
nist:
- DE.CM
observable:
- name: src_user
type: User
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- SidHistory
- TargetSid
- TargetDomainName
- user
- src_user
- Logon_ID
risk_score: 90
security_domain: endpoint
@@ -0,0 +1,72 @@
name: Windows AD Replication Service Traffic
id: c6e24183-a5f4-4b2a-ad01-2eb456d09b67
version: 1
date: '2022-11-26'
author: Steven Dick
type: TTP
datamodel:
- Network_Traffic
- Network_Sessions
description: This search looks for evidence of Active Directory replication traffic [MS-DRSR] from unexpected sources.
This traffic is often seen exclusively between Domain Controllers for AD database replication.
Any detections from non-domain controller source to a domain controller may indicate the usage of DCSync or DCShadow credential dumping techniques.
search: ' | tstats `security_content_summariesonly` count values(All_Traffic.transport) as transport values(All_Traffic.user) as user
values(All_Traffic.src_category) as src_category values(All_Traffic.dest_category) as dest_category min(_time) as firstTime max(_time) as lastTime
from datamodel=Network_Traffic where All_Traffic.app IN ("ms-dc-replication","*drsr*","ad drs") by All_Traffic.src All_Traffic.dest All_Traffic.app
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `drop_dm_object_name("All_Traffic")`
| `active_directory_replication_traffic_from_unknown_source_filter`
| `windows_ad_replication_service_traffic_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
application aware firewall or proxy logs into the Network Datamodel. Categorize
all known domain controller Assets servers with an appropriate category for filtering.
known_false_positives: New domain controllers or certian scripts run by administrators.
references:
- https://adsecurity.org/?p=1729
- https://attack.mitre.org/techniques/T1003/006/
- https://attack.mitre.org/techniques/T1207/
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 100
context:
- Source:Endpoint
- Stage:Credential Access
dataset:
- UPDATE_DATASET_URL
impact: 100
kill_chain_phases:
- Exploitation
- Actions on Objectives
message: Active Directory Replication Traffic from Unknown Source - $src$
mitre_attack_id:
- T1003
- T1003.006
- T1207
nist:
- DE.CM
observable:
- name: dest
type: IP Address
role:
- Victim
- name: src
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- All_Traffic.src
- All_Traffic.dest
- All_Traffic.app
risk_score: 100
security_domain: network
@@ -0,0 +1,57 @@
name: Windows AD Rogue Domain Controller Network Activity
id: c4aeeeef-da7f-4338-b3ba-553cbcbe2138
version: 1
date: '2022-09-08'
author: Dean Luxton
type: TTP
datamodel: []
description: This detection is looking at zeek wiredata for specific replication RPC calls being performed from a device which is not a domain controller.
If you would like to capture these RPC calls using Splunk Stream, please vote for my idea here https://ideas.splunk.com/ideas/APPSID-I-619 ;)
search: '`zeek_rpc` DrsReplicaAdd OR DRSGetNCChanges
| where NOT (dest_category="Domain Controller") OR NOT (src_category="Domain Controller")
| fillnull value="Unknown" src_category, dest_category
| table _time endpoint operation src src_category dest dest_category | `rogue_dc_network_activity_filter`'
how_to_implement: Run zeek on domain controllers to capture the DCE RPC calls, ensure the domain controller categories are defined in Assets and Identities.
known_false_positives: None.
references:
- https://adsecurity.org/?p=1729
tags:
analytic_story:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
cis20:
- CIS 4
- CIS 6
confidence: 100
context:
- Source:IPS
- Stage:Defense Evasion
dataset:
- https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1207/mimikatz/zeek-dce_rpc.log
impact: 100
kill_chain_phases:
- Actions on Objectives
message: Rogue DC Activity Detected from $src_category$ device $src$ to $dest$ ($dest_category$)
mitre_attack_id:
- T1207
nist:
- DE.CM
observable:
- name: src
type: IP Address
role:
- Attacker
- name: dest
type: IP Address
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- src
- dest
risk_score: 100
security_domain: network
+69
View File
@@ -0,0 +1,69 @@
Category,SubCategory,GUID
System,,{69979848-797A-11D9-BED3-505054503030}
System,Security State Change,{0CCE9210-69AE-11D9-BED3-505054503030}
System,Security System Extension,{0CCE9211-69AE-11D9-BED3-505054503030}
System,System Integrity,{0CCE9212-69AE-11D9-BED3-505054503030}
System,IPsec Driver,{0CCE9213-69AE-11D9-BED3-505054503030}
System,Other System Events,{0CCE9214-69AE-11D9-BED3-505054503030}
Logon/Logoff,,{69979849-797A-11D9-BED3-505054503030}
Logon/Logoff,Logon,{0CCE9215-69AE-11D9-BED3-505054503030}
Logon/Logoff,Logoff,{0CCE9216-69AE-11D9-BED3-505054503030}
Logon/Logoff,Account Lockout,{0CCE9217-69AE-11D9-BED3-505054503030}
Logon/Logoff,IPsec Main Mode,{0CCE9218-69AE-11D9-BED3-505054503030}
Logon/Logoff,IPsec Quick Mode,{0CCE9219-69AE-11D9-BED3-505054503030}
Logon/Logoff,IPsec Extended Mode,{0CCE921A-69AE-11D9-BED3-505054503030}
Logon/Logoff,Special Logon,{0CCE921B-69AE-11D9-BED3-505054503030}
Logon/Logoff,Other Logon/Logoff Events,{0CCE921C-69AE-11D9-BED3-505054503030}
Logon/Logoff,Network Policy Server,{0CCE9243-69AE-11D9-BED3-505054503030}
Logon/Logoff,User / Device Claims,{0CCE9247-69AE-11D9-BED3-505054503030}
Logon/Logoff,Group Membership,{0CCE9249-69AE-11D9-BED3-505054503030}
Object Access,,{6997984A-797A-11D9-BED3-505054503030}
Object Access,File System,{0CCE921D-69AE-11D9-BED3-505054503030}
Object Access,Registry,{0CCE921E-69AE-11D9-BED3-505054503030}
Object Access,Kernel Object,{0CCE921F-69AE-11D9-BED3-505054503030}
Object Access,SAM,{0CCE9220-69AE-11D9-BED3-505054503030}
Object Access,Certification Services,{0CCE9221-69AE-11D9-BED3-505054503030}
Object Access,Application Generated,{0CCE9222-69AE-11D9-BED3-505054503030}
Object Access,Handle Manipulation,{0CCE9223-69AE-11D9-BED3-505054503030}
Object Access,File Share,{0CCE9224-69AE-11D9-BED3-505054503030}
Object Access,Filtering Platform Packet Drop,{0CCE9225-69AE-11D9-BED3-505054503030}
Object Access,Filtering Platform Connection,{0CCE9226-69AE-11D9-BED3-505054503030}
Object Access,Other Object Access Events,{0CCE9227-69AE-11D9-BED3-505054503030}
Object Access,Detailed File Share,{0CCE9244-69AE-11D9-BED3-505054503030}
Object Access,Removable Storage,{0CCE9245-69AE-11D9-BED3-505054503030}
Object Access,Central Policy Staging,{0CCE9246-69AE-11D9-BED3-505054503030}
Privilege Use,,{6997984B-797A-11D9-BED3-505054503030}
Privilege Use,Sensitive Privilege Use,{0CCE9228-69AE-11D9-BED3-505054503030}
Privilege Use,Non Sensitive Privilege Use,{0CCE9229-69AE-11D9-BED3-505054503030}
Privilege Use,Other Privilege Use Events,{0CCE922A-69AE-11D9-BED3-505054503030}
Detailed Tracking,,{6997984C-797A-11D9-BED3-505054503030}
Detailed Tracking,Process Creation,{0CCE922B-69AE-11D9-BED3-505054503030}
Detailed Tracking,Process Termination,{0CCE922C-69AE-11D9-BED3-505054503030}
Detailed Tracking,DPAPI Activity,{0CCE922D-69AE-11D9-BED3-505054503030}
Detailed Tracking,RPC Events,{0CCE922E-69AE-11D9-BED3-505054503030}
Detailed Tracking,Plug and Play Events,{0CCE9248-69AE-11D9-BED3-505054503030}
Detailed Tracking,Token Right Adjusted Events,{0CCE924A-69AE-11D9-BED3-505054503030}
Policy Change,,{6997984D-797A-11D9-BED3-505054503030}
Policy Change,Audit Policy Change,{0CCE922F-69AE-11D9-BED3-505054503030}
Policy Change,Authentication Policy Change,{0CCE9230-69AE-11D9-BED3-505054503030}
Policy Change,Authorization Policy Change,{0CCE9231-69AE-11D9-BED3-505054503030}
Policy Change,MPSSVC Rule-Level Policy Change,{0CCE9232-69AE-11D9-BED3-505054503030}
Policy Change,Filtering Platform Policy Change,{0CCE9233-69AE-11D9-BED3-505054503030}
Policy Change,Other Policy Change Events,{0CCE9234-69AE-11D9-BED3-505054503030}
Account Management,,{6997984E-797A-11D9-BED3-505054503030}
Account Management,User Account Management,{0CCE9235-69AE-11D9-BED3-505054503030}
Account Management,Computer Account Management,{0CCE9236-69AE-11D9-BED3-505054503030}
Account Management,Security Group Management,{0CCE9237-69AE-11D9-BED3-505054503030}
Account Management,Distribution Group Management,{0CCE9238-69AE-11D9-BED3-505054503030}
Account Management,Application Group Management,{0CCE9239-69AE-11D9-BED3-505054503030}
Account Management,Other Account Management Events,{0CCE923A-69AE-11D9-BED3-505054503030}
DS Access,,{6997984F-797A-11D9-BED3-505054503030}
DS Access,Directory Service Access,{0CCE923B-69AE-11D9-BED3-505054503030}
DS Access,Directory Service Changes,{0CCE923C-69AE-11D9-BED3-505054503030}
DS Access,Directory Service Replication,{0CCE923D-69AE-11D9-BED3-505054503030}
DS Access,Detailed Directory Service Replication,{0CCE923E-69AE-11D9-BED3-505054503030}
Account Logon,,{69979850-797A-11D9-BED3-505054503030}
Account Logon,Credential Validation,{0CCE923F-69AE-11D9-BED3-505054503030}
Account Logon,Kerberos Service Ticket Operations,{0CCE9240-69AE-11D9-BED3-505054503030}
Account Logon,Other Account Logon Events,{0CCE9241-69AE-11D9-BED3-505054503030}
Account Logon,Kerberos Authentication Service,{0CCE9242-69AE-11D9-BED3-505054503030}
1 Category SubCategory GUID
2 System {69979848-797A-11D9-BED3-505054503030}
3 System Security State Change {0CCE9210-69AE-11D9-BED3-505054503030}
4 System Security System Extension {0CCE9211-69AE-11D9-BED3-505054503030}
5 System System Integrity {0CCE9212-69AE-11D9-BED3-505054503030}
6 System IPsec Driver {0CCE9213-69AE-11D9-BED3-505054503030}
7 System Other System Events {0CCE9214-69AE-11D9-BED3-505054503030}
8 Logon/Logoff {69979849-797A-11D9-BED3-505054503030}
9 Logon/Logoff Logon {0CCE9215-69AE-11D9-BED3-505054503030}
10 Logon/Logoff Logoff {0CCE9216-69AE-11D9-BED3-505054503030}
11 Logon/Logoff Account Lockout {0CCE9217-69AE-11D9-BED3-505054503030}
12 Logon/Logoff IPsec Main Mode {0CCE9218-69AE-11D9-BED3-505054503030}
13 Logon/Logoff IPsec Quick Mode {0CCE9219-69AE-11D9-BED3-505054503030}
14 Logon/Logoff IPsec Extended Mode {0CCE921A-69AE-11D9-BED3-505054503030}
15 Logon/Logoff Special Logon {0CCE921B-69AE-11D9-BED3-505054503030}
16 Logon/Logoff Other Logon/Logoff Events {0CCE921C-69AE-11D9-BED3-505054503030}
17 Logon/Logoff Network Policy Server {0CCE9243-69AE-11D9-BED3-505054503030}
18 Logon/Logoff User / Device Claims {0CCE9247-69AE-11D9-BED3-505054503030}
19 Logon/Logoff Group Membership {0CCE9249-69AE-11D9-BED3-505054503030}
20 Object Access {6997984A-797A-11D9-BED3-505054503030}
21 Object Access File System {0CCE921D-69AE-11D9-BED3-505054503030}
22 Object Access Registry {0CCE921E-69AE-11D9-BED3-505054503030}
23 Object Access Kernel Object {0CCE921F-69AE-11D9-BED3-505054503030}
24 Object Access SAM {0CCE9220-69AE-11D9-BED3-505054503030}
25 Object Access Certification Services {0CCE9221-69AE-11D9-BED3-505054503030}
26 Object Access Application Generated {0CCE9222-69AE-11D9-BED3-505054503030}
27 Object Access Handle Manipulation {0CCE9223-69AE-11D9-BED3-505054503030}
28 Object Access File Share {0CCE9224-69AE-11D9-BED3-505054503030}
29 Object Access Filtering Platform Packet Drop {0CCE9225-69AE-11D9-BED3-505054503030}
30 Object Access Filtering Platform Connection {0CCE9226-69AE-11D9-BED3-505054503030}
31 Object Access Other Object Access Events {0CCE9227-69AE-11D9-BED3-505054503030}
32 Object Access Detailed File Share {0CCE9244-69AE-11D9-BED3-505054503030}
33 Object Access Removable Storage {0CCE9245-69AE-11D9-BED3-505054503030}
34 Object Access Central Policy Staging {0CCE9246-69AE-11D9-BED3-505054503030}
35 Privilege Use {6997984B-797A-11D9-BED3-505054503030}
36 Privilege Use Sensitive Privilege Use {0CCE9228-69AE-11D9-BED3-505054503030}
37 Privilege Use Non Sensitive Privilege Use {0CCE9229-69AE-11D9-BED3-505054503030}
38 Privilege Use Other Privilege Use Events {0CCE922A-69AE-11D9-BED3-505054503030}
39 Detailed Tracking {6997984C-797A-11D9-BED3-505054503030}
40 Detailed Tracking Process Creation {0CCE922B-69AE-11D9-BED3-505054503030}
41 Detailed Tracking Process Termination {0CCE922C-69AE-11D9-BED3-505054503030}
42 Detailed Tracking DPAPI Activity {0CCE922D-69AE-11D9-BED3-505054503030}
43 Detailed Tracking RPC Events {0CCE922E-69AE-11D9-BED3-505054503030}
44 Detailed Tracking Plug and Play Events {0CCE9248-69AE-11D9-BED3-505054503030}
45 Detailed Tracking Token Right Adjusted Events {0CCE924A-69AE-11D9-BED3-505054503030}
46 Policy Change {6997984D-797A-11D9-BED3-505054503030}
47 Policy Change Audit Policy Change {0CCE922F-69AE-11D9-BED3-505054503030}
48 Policy Change Authentication Policy Change {0CCE9230-69AE-11D9-BED3-505054503030}
49 Policy Change Authorization Policy Change {0CCE9231-69AE-11D9-BED3-505054503030}
50 Policy Change MPSSVC Rule-Level Policy Change {0CCE9232-69AE-11D9-BED3-505054503030}
51 Policy Change Filtering Platform Policy Change {0CCE9233-69AE-11D9-BED3-505054503030}
52 Policy Change Other Policy Change Events {0CCE9234-69AE-11D9-BED3-505054503030}
53 Account Management {6997984E-797A-11D9-BED3-505054503030}
54 Account Management User Account Management {0CCE9235-69AE-11D9-BED3-505054503030}
55 Account Management Computer Account Management {0CCE9236-69AE-11D9-BED3-505054503030}
56 Account Management Security Group Management {0CCE9237-69AE-11D9-BED3-505054503030}
57 Account Management Distribution Group Management {0CCE9238-69AE-11D9-BED3-505054503030}
58 Account Management Application Group Management {0CCE9239-69AE-11D9-BED3-505054503030}
59 Account Management Other Account Management Events {0CCE923A-69AE-11D9-BED3-505054503030}
60 DS Access {6997984F-797A-11D9-BED3-505054503030}
61 DS Access Directory Service Access {0CCE923B-69AE-11D9-BED3-505054503030}
62 DS Access Directory Service Changes {0CCE923C-69AE-11D9-BED3-505054503030}
63 DS Access Directory Service Replication {0CCE923D-69AE-11D9-BED3-505054503030}
64 DS Access Detailed Directory Service Replication {0CCE923E-69AE-11D9-BED3-505054503030}
65 Account Logon {69979850-797A-11D9-BED3-505054503030}
66 Account Logon Credential Validation {0CCE923F-69AE-11D9-BED3-505054503030}
67 Account Logon Kerberos Service Ticket Operations {0CCE9240-69AE-11D9-BED3-505054503030}
68 Account Logon Other Account Logon Events {0CCE9241-69AE-11D9-BED3-505054503030}
69 Account Logon Kerberos Authentication Service {0CCE9242-69AE-11D9-BED3-505054503030}
+7
View File
@@ -0,0 +1,7 @@
description: List of GUIDs associated with Windows advanced audit policies
filename: advanced_audit_policy_guids.csv
name: advanced_audit_policy_guids
default_match: 'false'
match_type: WILDCARD(GUID)
min_matches: 1
case_sensitive_match: 'false'
+1 -1
View File
@@ -1,4 +1,4 @@
definition: eventtype=wineventlog_security OR source="XmlWinEventLog:Security"
definition: eventtype=wineventlog_security OR Channel=security OR source=XmlWinEventLog:Security
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: wineventlog_security
@@ -0,0 +1,23 @@
name: BishopFox Sliver Adversary Emulation Framework
id: 8c2e2cba-3fd8-424f-a890-5080bdaf3f31
version: 1
date: '2023-01-24'
author: Michael Haag, Splunk
description: The following analytic story providers visibility into the latest adversary TTPs in regard to the use of Sliver. Sliver has gained more traction with adversaries as it is often seen as an alternative to Cobalt Strike. It is designed to be scalable and can be used by organizations of all sizes to perform security testing. Sliver is highly modular and contains an Extension package manager (armory) allowing easy install (automatic compilation) of various 3rd party tools such as BOFs and .NET tooling like Ghostpack (Rubeus, Seatbelt, SharpUp, Certify, and so forth) (CyberReason,2023).
narrative: Sliver is an open source cross-platform adversary emulation/red team framework produced by BishopFox.
references:
- https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors
- https://www.ncsc.gov.uk/files/Advisory%20Further%20TTPs%20associated%20with%20SVR%20cyber%20actors.pdf
- https://www.proofpoint.com/uk/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity
- https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control
- https://github.com/sliverarmory/armory
- https://github.com/BishopFox/sliver
tags:
analytic_story: BishopFox Sliver Adversary Emulation Framework
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,37 @@
name: Sneaky Active Directory Persistence Tricks
id: f676c4c1-c769-4ecb-9611-5fd85b497c56
version: 1
date: '2022-08-29'
author: Dean Luxton, Mauricio Velazco, Splunk
description: Monitor for activities and techniques associated with Windows Active Directory persistence techniques.
narrative: Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access.
Active Directory is a centralized and hierarchical database that stores information about users, computers, and other resources on a network. It provides secure and efficient management
of these resources and enables administrators to enforce security policies and delegate administrative tasks.\
In 2015 Active Directory security researcher Sean Metcalf published a blog post titled `Sneaky Active Directory Persistence Tricks`. In this blog post,
Sean described several methods through which an attacker could persist administrative access on an Active Directory network after having Domain Admin level rights for
a short period of time. At the time of writing, 8 years after the initial blog post, most of these techniques are still possible since they abuse legitimate administrative functionality and not software vulnerabilities.
Security engineers defending Active Directory networks should be aware of these technique available to adversaries post exploitation and deploy both preventive and detective security controls for them.\
This analytic story groups detection opportunities for most of the techniques described on Seans blog post as well as other high impact attacks against Active Directory networks and Domain Controllers like DCSync and DCShadow.
For some of these detection opportunities, it is necessary to enable the necessary GPOs and SACLs required, otherwise the event codes will not trigger. Each detection includes a list of requirements for enabling logging.
references:
- https://adsecurity.org/?p=1929
- https://www.youtube.com/watch?v=Lz6haohGAMc&feature=youtu.be
- https://adsecurity.org/wp-content/uploads/2015/09/DEFCON23-2015-Metcalf-RedvsBlue-ADAttackAndDefense-Final.pdf
- https://attack.mitre.org/tactics/TA0003/
- https://www.dcshadow.com
- https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2
- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
tags:
analytic_story: Windows Domain Controller Attacks
category:
- Adversary Tactics
- Account Compromise
- Lateral Movement
- Privilege Escalation
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,13 @@
name: Disabling Windows Local Security Authority Defences via Registry Unit Test
tests:
- name: Disabling Windows Local Security Authority Defences via Registry
file: endpoint/disabling_windows_local_security_authority_defences_via_registry.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_lsa_protection/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Notepad with no Command Line Arguments Unit Test
tests:
- name: Notepad with no Command Line Arguments
file: endpoint/notepad_with_no_command_line_arguments.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: notepad_windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/notepad_windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD AdminSDHolder ACL Modified Unit Test
tests:
- name: Windows AD AdminSDHolder ACL Modified
file: endpoint/windows_ad_adminsdholder_acl_modified.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/adminsdholder_modified/windows-security.log
source: XmlWinEventLog
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Cross Domain SID History Addition Unit Test
tests:
- name: Windows AD Cross Domain SID History Addition
file: endpoint/windows_ad_cross_domain_sid_history_addition.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log
source: XmlWinEventLog
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Domain Controller Promotion Unit Test
tests:
- name: Windows AD Domain Controller Promotion
file: endpoint/windows_ad_domain_controller_promotion.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/dc_promo/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD DSRM Account Changes Unit Test
tests:
- name: Windows AD DSRM Account Changes
file: endpoint/windows_ad_dsrm_account_changes.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD DSRM Password Reset Unit Test
tests:
- name: Windows AD DSRM Password Reset
file: endpoint/windows_ad_dsrm_password_reset.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Replication Request Initiated by User Account Test
tests:
- name: Windows AD Replication Request Initiated by User Account
file: endpoint/windows_ad_replication_request_initiated_by_user_account.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,14 @@
name: Windows AD Replication Request Initiated from Unsanctioned Location Test
tests:
- name: Windows AD Replication Request Initiated from Unsanctioned Location
file: endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Same Domain SID History Addition Unit Test
tests:
- name: Windows AD Same Domain SID History Addition
file: endpoint/windows_ad_same_domain_sid_history_addition.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD ServicePrincipalName Added To Domain Account Unit Test
tests:
- name: Windows AD ServicePrincipalName Added To Domain Account
file: endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log
source: XmlWinEventLog
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Short Lived Domain Account ServicePrincipalName Unit Test
tests:
- name: Windows AD Short Lived Domain Account ServicePrincipalName
file: endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/short_lived_service_principal_name/windows-security.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Short Lived Domain Controller SPN Attribute Unit Test
tests:
- name: Windows AD Short Lived Domain Controller SPN Attribute
file: endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/mimikatz/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Short Lived Server Object Unit Test
tests:
- name: Windows Short Lived AD Server Object
file: endpoint/windows_ad_short_lived_server_object.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/short_lived_server_object/windows-security.log
source: XmlWinEventLog
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD SID History Attribute Modified
tests:
- name: Windows AD SID History Attribute Modified
file: endpoint/windows_ad_sid_history_attribute_modified.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/sid_history2/windows-security.log
source: XmlWinEventLog
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -6,8 +6,8 @@ tests:
earliest_time: -24h
latest_time: now
attack_data:
- file_name: 7045_kerneldrivers.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/7045_kerneldrivers.log
source: WinEventLog:System
sourcetype: WinEventLog
- file_name: xml7045_windows-system.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/xml7045_windows-system.log
source: XmlWinEventLog:System
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows Process Injection into Notepad Unit Test
tests:
- name: Windows Process Injection into Notepad
file: endpoint/windows_process_injection_into_notepad.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: T1055_windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/T1055_windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows Service Create SliverC2 Unit Test
tests:
- name: Windows Service Create SliverC2
file: endpoint/windows_service_create_sliverc2.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: sliver_windows-system.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/sliver_windows-system.log
source: XmlWinEventLog:System
sourcetype: XmlWinEventLog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Domain Controller Audit Policy Disabled Unit Test
tests:
- name: Windows AD Domain Controller Audit Policy Disabled
file: endpoint/windows_ad_domain_controller_audit_policy_disabled.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_gpo/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Domain Replication ACL Addition Unit Test
tests:
- name: Windows AD Domain Replication ACL Addition
file: endpoint/windows_ad_domain_replication_acl_addition.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/aclmodification/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,15 @@
name: Windows AD Privileged Account SID History Addition Unit Test
tests:
- name: Windows AD Privileged Account SID History Addition
file: experimental/windows_ad_privileged_account_sid_history_addition.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security-xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log
source: XmlWinEventLog:Security
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows AD Rogue Domain Controller Network Activity Unit Test
tests:
- name: Windows AD Rogue Domain Controller Network Activity
file: network/windows_ad_rogue_domain_controller_network_activity.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: zeek-dce_rpc.log
data: https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1207/mimikatz/zeek-dce_rpc.log
source: /opt/zeek/logs/current/dce_rpc.log
sourcetype: bro:dce_rpc:json
update_timestamp: true