diff --git a/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml b/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml index 5265bd86ff..9f7ff27e72 100644 --- a/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml +++ b/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml @@ -20,4 +20,4 @@ sourcetype: "{{ sourcetype }}" rename-source: "{{ source }}" index: "{{ index }}" - status_code: 201 \ No newline at end of file + status_code: 201 diff --git a/bin/docker_detection_tester/modules/validate_args.py b/bin/docker_detection_tester/modules/validate_args.py index a5ff54e475..9ad7cc7942 100644 --- a/bin/docker_detection_tester/modules/validate_args.py +++ b/bin/docker_detection_tester/modules/validate_args.py @@ -142,9 +142,14 @@ setup_schema = { "URL_TOOLBOX": { "app_number": 2734, "app_version": "1.9.2", - "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz", - }, - "SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": { + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz" + }, + "SPLUNK_TA_FIX_WINDOWS":{ + "app_number": 9999, + "app_version": "1.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz" + }, + "SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": { "app_number": 3110, "app_version": "4.5.2", "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_452.tgz", diff --git a/bin/docker_detection_tester/test_config_github_actions.json b/bin/docker_detection_tester/test_config_github_actions.json index dac273e5e3..898ca9183f 100644 --- a/bin/docker_detection_tester/test_config_github_actions.json +++ b/bin/docker_detection_tester/test_config_github_actions.json @@ -1,9 +1,109 @@ { "apps": { - "ADD_ON_FOR_LINUX_SYSMON": { - "app_number": 6176, - "app_version": "1.0.4", - "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz" + "Splunk Add-on for CrowdStrike FDR": { + "app_number": 5579, + "app_version": "1.2.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_120.tgz" + }, + "ADD_ON_FOR_LINUX_SYSMON": { + "app_number": 6176, + "app_version": "1.0.4", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz" + }, + "PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": { + "app_number": 2757, + "app_version": "7.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/palo-alto-networks-add-on-for-splunk_710.tgz" + }, + "PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": { + "app_number": 2882, + "app_version": "3.0.2", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/python-for-scientific-computing-for-linux-64-bit_302.tgz" + }, + "SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE": { + "app_number": 3719, + "app_version": "1.3.2", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-amazon-kinesis-firehose_132.tgz" + }, + "SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": { + "app_number": 4055, + "app_version": "4.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_400.tgz" + }, + "SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": { + "app_number": 742, + "app_version": "8.5.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850.tgz" + }, + "SPLUNK_ADD_ON_FOR_NGINX": { + "app_number": 3258, + "app_version": "3.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-nginx_310.tgz" + }, + "SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS": { + "app_number": 5238, + "app_version": "8.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-forwarders_810.tgz" + }, + "SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA": { + "app_number": 5234, + "app_version": "8.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-wire-data_810.tgz" + }, + "SPLUNK_ADD_ON_FOR_SYSMON": { + "app_number": 5709, + "app_version": "3.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-sysmon_300.tgz" + }, + "SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": { + "app_number": 833, + "app_version": "8.6.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_860.tgz" + }, + "SPLUNK_APP_FOR_STREAM": { + "app_number": 1809, + "app_version": "8.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-app-for-stream_810.tgz" + }, + "SPLUNK_TA_FIX_WINDOWS":{ + "app_number": 9999, + "app_version": "1.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz" + }, + "SPLUNK_COMMON_INFORMATION_MODEL": { + "app_number": 1621, + "app_version": "5.0.1", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_501.tgz" + }, + "SPLUNK_ES_CONTENT_UPDATE": { + "app_number": 3449, + "app_version": null, + "local_path": null + }, + "SPLUNK_MACHINE_LEARNING_TOOLKIT": { + "app_number": 2890, + "app_version": "5.3.1", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-machine-learning-toolkit_531.tgz" + }, + "SPLUNK_TA_FOR_ZEEK": { + "app_number": 5466, + "app_version": "1.0.5", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-zeek_105.tgz" + }, + "URL_TOOLBOX": { + "app_number": 2734, + "app_version": "1.9.2", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz" + }, + "SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": { + "app_number": 3088, + "app_version": "4.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-cloud-platform_400.tgz" + }, + "SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": { + "app_number": 3110, + "app_version": "2.3.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-workspace_230.tgz" }, "PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": { "app_number": 2757, diff --git a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml index 4dd30a3070..30c1179d88 100644 --- a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml @@ -49,6 +49,7 @@ tags: - T1586.003 - T1110 - T1110.003 + - T1110.004 nist: - DE.CM observable: diff --git a/detections/cloud/gcp_multi_factor_authentication_disabled.yml b/detections/cloud/gcp_multi_factor_authentication_disabled.yml index e35f411f80..c6585220d1 100644 --- a/detections/cloud/gcp_multi_factor_authentication_disabled.yml +++ b/detections/cloud/gcp_multi_factor_authentication_disabled.yml @@ -42,6 +42,7 @@ tags: - T1586 - T1586.003 - T1556 + - T1556.006 nist: - DE.CM observable: diff --git a/detections/endpoint/disabling_windows_local_security_authority_defences_via_registry.yml b/detections/endpoint/disabling_windows_local_security_authority_defences_via_registry.yml new file mode 100644 index 0000000000..f58816a812 --- /dev/null +++ b/detections/endpoint/disabling_windows_local_security_authority_defences_via_registry.yml @@ -0,0 +1,76 @@ +name: Disabling Windows Local Security Authority Defences via Registry +id: 45cd08f8-a2c9-4f4e-baab-e1a0c624b0ab +version: 1 +date: '2022-09-09' +author: Dean Luxton +type: TTP +datamodel: +- Endpoint +description: This detection looks for the deletion of registry keys which disable LSA protection and MS Defender Device Guard. +search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Endpoint.Registry + where Registry.registry_path IN ("*\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\LsaCfgFlags", + "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\DeviceGuard\\*", "*\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\RunAsPPL") + Registry.action IN (deleted, unknown) by Registry.action Registry.registry_path + Registry.process_guid + | `drop_dm_object_name(Registry)` + | join type=outer process_guid [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by Processes.user Processes.process_name Processes.process + Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid + | `drop_dm_object_name(Processes)`] + | table _time action dest user parent_process_name parent_process process_name process + process_guid registry_path | `disabling_windows_local_security_authority_defences_via_registry_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Potential to be triggered by an administrator disabling protections for troubleshooting purposes. +references: +- https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection +- https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-manage +tags: + analytic_story: + - Windows Defence Evasion Tactics + - Windows Registry Abuse + asset_type: Endpoint + cis20: + - CIS 5 + - CIS 6 + - CIS 16 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_lsa_protection/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_credential_guard/windows-sysmon.log + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: An attempt to disable Windows LSA defences was detected on $dest$. The reg key $registry_path$ was deleted by $user$. + mitre_attack_id: + - T1556 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.action + - Registry.registry_path + - Registry.dest + - Registry.user + risk_score: 60 + security_domain: endpoint diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index dfdb55894e..cbe547f715 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement Commandline Parameters id: 8ce07472-496f-11ec-ab3b-3e22fbd008af -version: 2 -date: '2022-01-18' +version: 3 +date: '2023-02-24' author: Mauricio Velazco, Splunk type: TTP datamodel: @@ -14,11 +14,10 @@ description: This analytic looks for the presence of suspicious commandline para scripts leverage administrative shares and hardcoded parameters that can be used as a signature to detect its use. Red Teams and adversaries alike may leverage Impackets tools for lateral movement and remote code execution. -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where (Processes.process = "*/c* \\\\127.0.0.1\\*" - OR Processes.process= "*/c* 2>&1") by Processes.dest Processes.user Processes.parent_process_name - Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe (Processes.process = "*/Q /c * \\\\127.0.0.1\\*$*" AND Processes.process IN ("*2>&1*","*2>&1*")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `impacket_lateral_movement_commandline_parameters_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your diff --git a/detections/endpoint/notepad_with_no_command_line_arguments.yml b/detections/endpoint/notepad_with_no_command_line_arguments.yml new file mode 100644 index 0000000000..fff9217112 --- /dev/null +++ b/detections/endpoint/notepad_with_no_command_line_arguments.yml @@ -0,0 +1,75 @@ +name: Notepad with no Command Line Arguments +id: 5adbc5f1-9a2f-41c1-a810-f37e015f8179 +version: 1 +date: '2023-02-22' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies behavior related to default SliverC2 framework where it will inject into Notepad.exe and spawn Notepad.exe with no command line arguments. In testing, this is a common procedure for SliverC2 usage, however may be modified or changed. + From Microsoft, "The Sideload, SpawnDll, and Execute-Assembly commands spawn and inject into notepad.exe by default. The following query finds process creation events where the same process creates and injects into notepad.exe within 10 seconds." +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=notepad.exe AND Processes.action!="blocked" by host _time span=1h Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process Processes.parent_process_name Processes.parent_process + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | regex process="(?i)(notepad\.exe.{0,4}$)" + | `notepad_with_no_command_line_arguments_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives may be present and filtering may need to occur based on organization endpoint behavior. +references: +- https://www.microsoft.com/en-us/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/ +- https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors#Purple-Team-Section +tags: + analytic_story: + - BishopFox Sliver Adversary Emulation Framework + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/notepad_windows-sysmon.log + impact: 50 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ with no command line arguments. + mitre_attack_id: + - T1055 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + risk_score: 35 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 7cf8f71de9..888d484319 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -57,6 +57,7 @@ tags: - Qakbot - Chaos Ransomware - AsyncRAT + - Sneaky Active Directory Persistence Tricks asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index aea9e3c110..1e9826eb13 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -47,21 +47,28 @@ tags: impact: 70 kill_chain_phases: - Actions on Objectives - message: Suspicious $Processes.process_path.file_path$ process running with an uncommon - parent process $Processes.parent_process_name$ + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to add a registry entry. mitre_attack_id: - T1112 nist: - DE.CM observable: - - name: dest - type: Endpoint + - name: user + type: User role: - Victim - - name: Processes.process_path.file_path - type: File Name + - name: dest + type: Hostname role: - - Attacker + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Enterprise - Splunk Enterprise Security @@ -78,4 +85,4 @@ tags: risk_score: 35 security_domain: endpoint supported_tas: - - Splunk_TA_microsoft_sysmon + - Splunk_TA_microsoft_sysmon \ No newline at end of file diff --git a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml index 7c32281b0d..9468a3bdb9 100644 --- a/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml +++ b/detections/endpoint/suspicious_regsvr32_register_suspicious_path.yml @@ -1,20 +1,18 @@ name: Suspicious Regsvr32 Register Suspicious Path id: 62732736-6250-11eb-ae93-0242ac130002 -version: 2 -date: '2021-01-28' +version: 3 +date: '2023-03-02' author: Michael Haag, Splunk type: TTP datamodel: - Endpoint description: Adversaries may abuse Regsvr32.exe to proxy execution of malicious code - by using non-standard file extensions to load malciious DLLs. Upon investigating, + by using non-standard file extensions to load DLLs. Upon investigating, look for network connections to remote destinations (internal or external). Review additional parrallel processes and child processes for additional activity. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` (Processes.process=*appdata* - OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll - Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user - Processes.parent_process Processes.process_name Processes.process Processes.original_file_name + as lastTime from datamodel=Endpoint.Processes where `process_regsvr32` Processes.process IN ("*\\appdata\\*", "*\\programdata\\*","*\\windows\\temp\\*") NOT (Processes.process IN ("*.dll*", "*.ax*", "*.ocx*")) + by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.original_file_name Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_regsvr32_register_suspicious_path_filter`' how_to_implement: You must be ingesting endpoint data that tracks process activity, @@ -54,22 +52,29 @@ tags: impact: 70 kill_chain_phases: - Actions on Objectives - message: Suspicious $Processes.process_path.file_path$ process potentially loading - malicious code + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to evade detection by using a non-standard file extension. mitre_attack_id: - T1218 - T1218.010 nist: - DE.CM observable: - - name: dest - type: Endpoint + - name: user + type: User role: - Victim - - name: Processes.process_path.file_path - type: File Name + - name: dest + type: Hostname role: - - Attacker + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Enterprise - Splunk Enterprise Security @@ -90,4 +95,4 @@ tags: risk_score: 35 security_domain: endpoint supported_tas: - - Splunk_TA_microsoft_sysmon + - Splunk_TA_microsoft_sysmon \ No newline at end of file diff --git a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml index c8be5358d0..38bc57429d 100644 --- a/detections/endpoint/suspicious_rundll32_dllregisterserver.yml +++ b/detections/endpoint/suspicious_rundll32_dllregisterserver.yml @@ -52,7 +52,7 @@ tags: impact: 70 kill_chain_phases: - Actions on Objectives - message: $Processes.process_path.file_path$ process potentially loading malicious + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to register a DLL. code mitre_attack_id: - T1218 @@ -61,14 +61,22 @@ tags: - PR.PT - DE.CM observable: - - name: dest - type: Endpoint + - name: user + type: User role: - Victim - - name: Processes.process_path.file_path - type: File Name + - name: dest + type: Hostname role: - - Attacker + - Victim + - name: parent_process_name + type: Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process product: - Splunk Enterprise - Splunk Enterprise Security @@ -89,4 +97,4 @@ tags: risk_score: 35 security_domain: endpoint supported_tas: - - Splunk_TA_microsoft_sysmon + - Splunk_TA_microsoft_sysmon \ No newline at end of file diff --git a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml new file mode 100644 index 0000000000..9218bbdecd --- /dev/null +++ b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml @@ -0,0 +1,76 @@ +name: Windows AD AdminSDHolder ACL Modified +id: 00d877c3-7b7b-443d-9562-6b231e2abab9 +version: 1 +date: '2022-11-15' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic identifies the modification of the Access Control List for the AdminSDHolder object within a Windows domain. Specifically, the + detection triggers on the addition of a new rule to the existing ACL. AdminSDHolder is an object located in the System Partition in Active Directory and is used as a + security template for objects that are members of certain privileged groups. Objects in these groups are enumerated and any objects with security descriptors that dont + match the AdminSDHolder ACL are flagged for updating. The Security Descriptor propagator (SDProp) process runs every 60 minutes on the PDC Emulator and re-stamps the object + Access Control List (ACL) with the security permissions set on the AdminSDHolder. An adversary who has obtained privileged access to a Windows Domain may modify the AdminSDHolder + ACL to establish persistence and allow an unprivileged user to take control of a domain. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=nTSecurityDescriptor OperationType="%%14674" ObjectDN="CN=AdminSDHolder,CN=System*" + | rex field=AttributeValue max_match=10000 "A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;(?PS-1-[0-59]-\d{2}-\d{8,10}-\d{8,10}-\d{8,10}-[1-9]\d{3})\)" + | stats values(added_user_sid) by _time, Computer, SubjectUserName, ObjectDN + | `windows_ad_adminsdholder_acl_modified_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for the AdminSDHolder object in order to log modifications. +known_false_positives: Adding new users or groups to the AdminSDHolder ACL is not usual. Filter as needed +references: +- https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory +- https://social.technet.microsoft.com/wiki/contents/articles/22331.adminsdholder-protected-groups-and-security-descriptor-propagator.aspx +- https://adsecurity.org/?p=1906 +- https://pentestlab.blog/2022/01/04/domain-persistence-adminsdholder/ +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 +- https://learn.microsoft.com/en-us/windows/win32/secauthz/access-control-lists +- https://medium.com/@cryps1s/detecting-windows-endpoint-compromise-with-sacls-cd748e10950 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/adminsdholder_modified/windows-security.log + impact: 80 + kill_chain_phases: + - Installation + - Actions on Objectives + message: The AdminSDHolder domain object has been modified on $Computer$ by $SubjectUserName$ + mitre_attack_id: + - T1546 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AttributeLDAPDisplayName + - OperationType + - ObjectDN + - Computer + - SubjectUserName + - AttributeValue + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml new file mode 100644 index 0000000000..e88f948647 --- /dev/null +++ b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml @@ -0,0 +1,75 @@ +name: Windows AD Cross Domain SID History Addition +id: 41bbb371-28ba-439c-bb5c-d9930c28365d +version: 1 +date: '2022-11-17' +author: Dean Luxton +type: TTP +datamodel: [] +description: The following analytic looks for changes to the sIDHistory AD attribute of user or computer objects within different domains. + The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access + continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries for inter-domain privilege escalation and persistence. +search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory IN ("%%1793", -) + | rex field=SidHistory "(^%{|^)(?P.*)(\-|\\\)" + | rex field=TargetSid "^(?P.*)(\-|\\\)" + | where SidHistoryMatch!=TargetSidmatch AND SidHistoryMatch!=TargetDomainName + | rename TargetSid as userSid + | table _time action status host user userSid SidHistory Logon_ID src_user + | `windows_ad_cross_domain_sid_history_addition_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcodes + `4738` and `4742`. The Advanced Security Audit policy settings + `Audit User Account Management` and `Audit Computer Account Management` + within `Account Management` all need to be enabled. +known_false_positives: Domain mergers and migrations may generate large volumes of false positives for this analytic. +references: +- https://adsecurity.org/?p=1772 +- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN +- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + - CIS 16 + confidence: 80 + context: + - Source:AD + - Stage:Persistence + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Active Directory SID History Attribute was added to $user$ by $src_user$ + mitre_attack_id: + - T1134.005 + - T1134 + nist: + - DE.CM + observable: + - name: src_user + type: User + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - SidHistory + - TargetSid + - TargetDomainName + - user + - src_user + - Logon_ID + risk_score: 80 + security_domain: endpoint + diff --git a/detections/endpoint/windows_ad_domain_controller_promotion.yml b/detections/endpoint/windows_ad_domain_controller_promotion.yml new file mode 100644 index 0000000000..dda3b1e0c4 --- /dev/null +++ b/detections/endpoint/windows_ad_domain_controller_promotion.yml @@ -0,0 +1,69 @@ +name: Windows AD Domain Controller Promotion +id: e633a0ef-2a6e-4ed7-b925-5ff999e5d1f0 +version: 1 +date: '2023-01-26' +author: Dean Luxton +type: TTP +datamodel: [] +description: This analytic identifies a genuine DC promotion event. Identifying when a computer assigns itself the + necessary SPNs to function as a domain controller. Note these events are triggered on the existing domain controllers, not the newly + joined domain controller. This detection will serve to identify rogue DCs added to the network. There are 2x detections within this analytic story + which identify DCShadow attacks, if you do not currently possess the logging for these detections, remove the where clause within this + detection to identify DCShadow activity. +search: "`wineventlog_security` EventCode=4742 ServicePrincipalNames IN (\"*E3514235-4B06-11D1-AB04-00C04FC2DCD2/*\"\ + , \"*GC/*\") \n| stats min(_time) as _time latest(ServicePrincipalNames) as ServicePrincipalNames,\ + \ values(signature) as signature, values(src_user) as src_user, values(user) as\ + \ user by Logon_ID, dvc\n| where src_user=user\n| rename Logon_ID as TargetLogonId,\ + \ user as dest\n| appendpipe [| map search=\"search `wineventlog_security` EventCode=4624\ + \ TargetLogonId=$TargetLogonId$\" | fields - dest, dvc, signature]\n| stats min(_time)\ + \ as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain,\ + \ values(user) as user, values(status) as status, values(src_category) as src_category,\ + \ values(src_ip) as src_ip values(ServicePrincipalNames) as ServicePrincipalNames\ + \ values(signature) as signature values(dest) as dest values(dvc) as dvc by TargetLogonId\n\ + | eval dest=trim(dest,\"$\") | `windows_ad_domain_controller_promotion_filter`" +how_to_implement: To successfully implement this search, you need to be ingesting eventcode + `4742`. The Advanced Security Audit policy setting `Audit Computer Account Management` + within `Account Management` needs to be enabled. +known_false_positives: None. +references: +- https://attack.mitre.org/techniques/T1207/ +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/dc_promo/windows-security-xml.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: AD Domain Controller Promotion Event Detected for $dest$ + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ServicePrincipalNames + - src_user + - user + - Logon_ID + - dvc + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_dsrm_account_changes.yml b/detections/endpoint/windows_ad_dsrm_account_changes.yml new file mode 100644 index 0000000000..934fe94634 --- /dev/null +++ b/detections/endpoint/windows_ad_dsrm_account_changes.yml @@ -0,0 +1,75 @@ +name: Windows AD DSRM Account Changes +id: 08cb291e-ea77-48e8-a95a-0799319bf056 +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: +- Endpoint +description: Aside from being used to promote genuine domain controllers, the DSRM (Directory Services Restore Mode) + account can be used to persist within a Domain. A DC can be configured to allow the DSRM account to logon & be + used in the same way as a local administrator account. This detection is looking for alterations to the behaviour + of the account via registry. +search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\System\\CurrentControlSet\\Control\\Lsa\\DSRMAdminLogonBehavior" + Registry.registry_value_data IN ("*1","*2") by Registry.action Registry.registry_path + Registry.registry_value_data Registry.registry_value_type Registry.process_guid + | `drop_dm_object_name(Registry)` + | join type=outer process_guid [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by Processes.user Processes.process_name Processes.process + Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid + | `drop_dm_object_name(Processes)`] + | table _time action dest user parent_process_name parent_process process_name process + process_guid registry_path registry_value_data registry_value_type | `windows_ad_dsrm_account_changes_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Disaster recovery events. +references: +- https://adsecurity.org/?p=1714 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Windows Registry Abuse + - Windows Persistence Techniques + asset_type: Endpoint + cis20: + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: DSRM Account Changes Initiated on $dest$ by $user$ + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.registry_value_data + - Registry.registry_path + - Registry.dest + - Registry.user + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_dsrm_password_reset.yml b/detections/endpoint/windows_ad_dsrm_password_reset.yml new file mode 100644 index 0000000000..3664351cc2 --- /dev/null +++ b/detections/endpoint/windows_ad_dsrm_password_reset.yml @@ -0,0 +1,65 @@ +name: Windows AD DSRM Password Reset +id: d1ab841c-36a6-46cf-b50f-b2b04b31182a +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: +- Change +description: Aside from being used to promote genuine domain controllers, the DSRM (Directory Services Restore Mode) + account can be used to persist within a Domain. A DC can be configured to allow the DSRM account to logon & be + used in the same way as a local administrator account. This detection is looking for any password reset attempts against that account. +search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Change + where All_Changes.result_id="4794" AND All_Changes.result="An attempt was made to + set the Directory Services Restore Mode administrator password" by All_Changes.action, + All_Changes.dest, All_Changes.src, All_Changes.user + | `drop_dm_object_name(All_Changes)` | `windows_ad_dsrm_password_reset_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode + `4794` and have the Advanced Security Audit policy + `Audit User Account Management` within `Account Management` enabled. +known_false_positives: Resetting the DSRM password for legitamate reasons, i.e. forgot the password. Disaster recovery. Deploying AD backdoor deliberately. +references: +- https://adsecurity.org/?p=1714 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: DSRM Account Password was reset on $dest$ by $user$ + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - All_Changes.result_id + - All_Changes.result + - All_Changes.action + - All_Changes.dest + - All_Changes.src + - All_Changes.user + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml new file mode 100644 index 0000000000..928ba49bab --- /dev/null +++ b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml @@ -0,0 +1,84 @@ +name: Windows AD Replication Request Initiated by User Account +id: 51307514-1236-49f6-8686-d46d93cc2821 +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: [] +description: This alert was written to detect activity associated with the DCSync attack. + When a domain controller receives a replication request, the user account permissions are validated, however no checks are performed to validate the request was initiated by a Domain Controller. + Once an attacker gains control of an account with the necessary privileges, they can request password hashes for any or all users within the domain. + This alert detects when a user account creates a handle to domainDNS with the necessary replication permissions. +search: '`wineventlog_security` EventCode=4662 ObjectType IN ("%{19195a5b-6da0-11d0-afd3-00c04fd930c9}", "domainDNS") AND Properties IN ("*Replicating Directory Changes All*", "*{1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}*", "*{9923a32a-3607-11d2-b9be-0000f87a36b2}*","*{1131f6ac-9c07-11d1-f79f-00c04fc2dcd2}*") AND AccessMask="0x100" AND NOT (SubjectUserSid="NT AUT*" OR SubjectUserSid="S-1-5-18" OR SubjectDomainName="Window Manager" OR SubjectUserName="*$") + | stats min(_time) as _time, count by SubjectDomainName, SubjectUserName, Computer, Logon_ID, ObjectName, ObjectServer, ObjectType, OperationType, status + | rename SubjectDomainName as Target_Domain, SubjectUserName as user, Logon_ID as TargetLogonId, _time as attack_time + | appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] + | table attack_time, AuthenticationPackageName, LogonProcessName, LogonType, TargetUserSid, Target_Domain, user, Computer, TargetLogonId, status, src_ip, src_category, ObjectName, ObjectServer, ObjectType, OperationType + | stats min(attack_time) as _time values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) as status, values(src_category) as src_category, values(src_ip) as src_ip by TargetLogonId + | `windows_ad_replication_request_initiated_by_user_account_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode `4662`. + The Advanced Security Audit policy settings `Audit Directory Services Access` + within `DS Access` needs to be enabled, as well as the following SACLs applied to the domain root + and all descendant objects. The principals `everybody`, `Domain Computers`, and `Domain Controllers` + auditing the permissions `Replicating Directory Changes`, `Replicating Directory Changes All`, and + `Replicating Directory Changes In Filtered Set` +known_false_positives: Azure AD Connect syncing operations. +references: +- https://adsecurity.org/?p=1729 +- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer +- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Source:AD + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Windows Active Directory Replication Request Initiated by User Account $user$ at $src_ip$ + mitre_attack_id: + - T1003.006 + - T1003 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectType + - Properties + - AccessMask + - SubjectDomainName + - SubjectUserName + - SubjectUserSid + - Computer + - Logon_ID + - ObjectName + - ObjectServer + - ObjectType + - OperationType + - status + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml new file mode 100644 index 0000000000..54787ae31f --- /dev/null +++ b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml @@ -0,0 +1,101 @@ +name: Windows AD Replication Request Initiated from Unsanctioned Location +id: 50998483-bb15-457b-a870-965080d9e3d3 +version: 1 +date: '2022-11-17' +author: Dean Luxton +type: TTP +datamodel: [] +description: This alert was written to detect activity associated with the DCSync attack performed by computer accounts. + When a domain controller receives a replication request, the account permissions are validated, however no checks are performed to validate the request was initiated by a Domain Controller. + Once an attacker gains control of an account with the necessary privileges, they can request password hashes for any or all users within the domain. + This alert detects when a computer account account creates a handle to domainDNS with the necessary replication permissions. These requests are then filtered to exclude where the events originate + from a known domain controller IP address. +search: '`wineventlog_security` EventCode=4662 ObjectType IN ("%{19195a5b-6da0-11d0-afd3-00c04fd930c9}", + "domainDNS") AND Properties IN ("*Replicating Directory Changes All*", "*{1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}*", + "*{9923a32a-3607-11d2-b9be-0000f87a36b2}*","*{1131f6ac-9c07-11d1-f79f-00c04fc2dcd2}*") + AND AccessMask="0x100" AND (SubjectUserSid="NT AUT*" OR SubjectUserSid="S-1-5-18" OR SubjectDomainName="Window Manager" OR SubjectUserName="*$") + + | stats min(_time) as attack_time, count by SubjectDomainName, SubjectUserName, + Computer, Logon_ID, ObjectName, ObjectServer, ObjectType, OperationType, status + + | rename SubjectDomainName as Target_Domain, SubjectUserName as user, Logon_ID as + TargetLogonId + + | appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] + + | table attack_time, AuthenticationPackageName, LogonProcessName, LogonType, TargetUserSid, + Target_Domain, user, Computer, TargetLogonId, status, src_ip, src_category, ObjectName, + ObjectServer, ObjectType, OperationType + + | stats min(attack_time) as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) + as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) + as status, values(src_category) as src_category, values(src_ip) as src_ip by TargetLogonId + + | search NOT src_category="domain_controller" | `windows_ad_replication_request_initiated_from_unsanctioned_location_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode `4662`. + The Advanced Security Audit policy settings `Audit Directory Services Access` + within `DS Access` needs to be enabled, as well as the following SACLs applied to the domain root + and all descendant objects. The principals `everybody`, `Domain Computers`, and `Domain Controllers` + auditing the permissions `Replicating Directory Changes`, `Replicating Directory Changes All`, and + `Replicating Directory Changes In Filtered Set` + Assets and Identities will also need to be configured, with the category of domain_controller added for domain controllers. +known_false_positives: Genuine DC promotion may trigger this alert. +references: +- https://adsecurity.org/?p=1729 +- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer +- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Source:AD + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Windows Active Directory Replication Request Initiated from Unsanctioned Location $src_ip$ by $user$ + mitre_attack_id: + - T1003.006 + - T1003 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectType + - Properties + - AccessMask + - SubjectDomainName + - SubjectUserName + - SubjectUserSid + - Computer + - Logon_ID + - ObjectName + - ObjectServer + - ObjectType + - OperationType + - status + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml new file mode 100644 index 0000000000..5f33a7ff26 --- /dev/null +++ b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml @@ -0,0 +1,78 @@ +name: Windows AD Same Domain SID History Addition +id: 5fde0b7c-df7a-40b1-9b3a-294c00f0289d +version: 2 +date: '2022-09-09' +author: Dean Luxton +type: TTP +datamodel: [] +description: The following analytic looks for changes to the sIDHistory AD attribute of user or computer objects which exist within the same domain. + The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access + continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries to stealthily grant access to a backdoor account within the same domain. + This analytic was written to pick up on activity via Mimikatz sid::patch. Please note there are additional avenues to abuse SID history such as DCShadow & Golden / Diamond tickets which won't be detected using these event codes. +search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory + IN ("%%1793", -) + | rex field=SidHistory "(^%{|^)(?P.*)(\-|\\\)" + | rex field=TargetSid "^(?P.*)(\-|\\\)" + | where SidHistoryMatch=TargetSidmatch OR SidHistoryMatch=TargetDomainName + | rename TargetSid as userSid, TargetDomainName as userDomainName + | table _time action status host user userSid userDomainName SidHistory Logon_ID src_user + | `windows_ad_same_domain_sid_history_addition_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcodes + `4738` and `4742`. The Advanced Security Audit policy settings + `Audit User Account Management` and `Audit Computer Account Management` + within `Account Management` all need to be enabled. SID resolution is not required.. +known_false_positives: Unknown +references: +- https://adsecurity.org/?p=1772 +- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN +- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute +- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Windows Persistence Techniques + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + - CIS 16 + confidence: 100 + context: + - Source:AD + - Stage:Persistence + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Active Directory SID History Attribute was added to $user$ by $src_user$ + mitre_attack_id: + - T1134.005 + - T1134 + nist: + - DE.CM + observable: + - name: src_user + type: User + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - SidHistory + - TargetSid + - TargetDomainName + - user + - src_user + - Logon_ID + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml b/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml new file mode 100644 index 0000000000..c0a7a9b437 --- /dev/null +++ b/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml @@ -0,0 +1,69 @@ +name: Windows AD ServicePrincipalName Added To Domain Account +id: 8a1259cb-0ea7-409c-8bfe-74bad89259f9 +version: 1 +date: '2022-11-17' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic identifies the addition of a Service Principal Name to a domain account. While this event may be part of a legitimate action part of certain administrative operations, + it may also be evidence of a persistence attack. Domain accounts with Servce Principal Names are vulnerable to a technique called Kerberoasting that enables attackers to potentially obtain the cleartext password + of the account by performing offline cracking. An adversary who has obtained privileged access to a domain environment may add an SPN to a privileged account to then leverage the Kerberoasting technique and attempt + to obtain its clertext password. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName OperationType="%%14674" + | stats values(ObjectDN) by _time, Computer, SubjectUserName, AttributeValue + | `windows_ad_serviceprincipalname_added_to_domain_account_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications. +known_false_positives: A Service Principal Name should only be added to an account when an application requires it. While infrequent, this detection may trigger on + legitimate actions. Filter as needed. +references: +- https://adsecurity.org/?p=3466 +- https://www.thehacker.recipes/ad/movement/dacl/targeted-kerberoasting +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 +- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting +tags: + analytic_story: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log + impact: 60 + kill_chain_phases: + - Installation + - Actions on Objectives + message: A Servince Principal Name for $ObjectDN$ was set by $SubjectUserName$ + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: ObjectDN + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectDN + - signature + - SubjectUserName + - Computer + risk_score: 30 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml b/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml new file mode 100644 index 0000000000..00364ccf19 --- /dev/null +++ b/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml @@ -0,0 +1,71 @@ +name: Windows AD Short Lived Domain Account ServicePrincipalName +id: b681977c-d90c-4efc-81a5-c58f945fb541 +version: 1 +date: '2022-11-18' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic identifies the addition of a Service Principal Name to a domain account that is quickly deleted within 5 minutes or less. While this event may be part of a legitimate action part of certain administrative operations, + it may also be evidence of a persistence attack. Domain accounts with Service Principal Names are vulnerable to a technique called Kerberoasting that enables attackers to potentially obtain the cleartext password + of the account by performing offline cracking. An adversary who has obtained privileged access to a domain environment may add an SPN to a privileged account to then leverage the Kerberoasting technique and attempt + to obtain its clertext password. To clean things up, the adversary may delete the SPN which will trigger this detection. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName + | transaction ObjectDN AttributeValue startswith=(EventCode=5136 OperationType="%%14674") endswith=(EventCode=5136 OperationType="%%14675") + | eval short_lived=case((duration<300),"TRUE") + | search short_lived = TRUE + | `windows_ad_short_lived_domain_account_serviceprincipalname_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications. +known_false_positives: A Service Principal Name should only be added to an account when an application requires it. Adding an SPN and quickly deleting it + is less common but may be part of legitimate action. Filter as needed. +references: +- https://adsecurity.org/?p=3466 +- https://www.thehacker.recipes/ad/movement/dacl/targeted-kerberoasting +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 +- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/short_lived_service_principal_name/windows-security.log + impact: 50 + kill_chain_phases: + - Installation + - Actions on Objectives + message: A Servince Principal Name for $ObjectDN$ was set and shortly deleted + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: ObjectDN + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectDN + - signature + - SubjectUserName + - Computer + risk_score: 40 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml b/detections/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml new file mode 100644 index 0000000000..e833fc8f8c --- /dev/null +++ b/detections/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml @@ -0,0 +1,78 @@ +name: Windows AD Short Lived Domain Controller SPN Attribute +id: 57e27f27-369c-4df8-af08-e8c7ee8373d4 +version: 2 +date: '2022-09-02' +author: Dean Luxton +type: TTP +datamodel: [] +description: The following analytic identifies when either a global catalog SPN or a DRS RPC SPN are temporarily added to an Active Directory computer object, both of which can be evidence of a DCShadow attack. + DCShadow allows an attacker who has obtained privileged access to register a rogue Domain Controller (DC). Once registered, the rogue DC may be able to inject + and replicate changes into the AD infrastructure for any domain object, including credentials and keys. This technique was initially released in 2018 by security researchers Benjamin Delpy and Vincent Le Toux. + No event logs are written for changes to AD attributes, allowing for stealthy backdoors to be implanted in the domain, or metadata such as timestamps overwritten to cover tracks. +search: '`wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName (AttributeValue="GC/*" OR AttributeValue="E3514235-4B06-11D1-AB04-00C04FC2DCD2/*") + | stats min(_time) as _time range(_time) as duration values(OperationType) as OperationType values(src_nt_domain) as src_nt_domain values(src_user) as src_user values(Computer) as Computer, values(ObjectDN) as ObjectDN by Logon_ID + | eval short_lived=case((duration<30),"TRUE") + | where short_lived="TRUE" AND mvcount(OperationType)>1 + | replace "%%14674" with "Value Added", "%%14675" with "Value Deleted" in OperationType + | rename Logon_ID as TargetLogonId + | appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] + | stats min(_time) as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) as status, values(src_category) as src_category, values(src_ip) as src_ip values(ObjectDN) as ObjectDN values(OperationType) as OperationType by TargetLogonId + | `windows_ad_short_lived_domain_controller_spn_attribute_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled, alongside a SACL for `everybody` to + `Write All Properties` applied to the domain root and all descendant objects. +known_false_positives: None. +references: +- https://www.dcshadow.com/ +- https://blog.netwrix.com/2022/09/28/dcshadow_attack/ +- https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2 +- https://attack.mitre.org/techniques/T1207/ +- https://blog.alsid.eu/dcshadow-explained-4510f52fc19d +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Short Lived Domain Controller SPN AD Attribute Triggered by $user$ from $src_ip$ + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AttributeLDAPDisplayName + - AttributeValue + - src_nt_domain + - src_user + - Computer + - ObjectDN + - Logon_ID + - signature + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_short_lived_server_object.yml b/detections/endpoint/windows_ad_short_lived_server_object.yml new file mode 100644 index 0000000000..ed5b2cf8c9 --- /dev/null +++ b/detections/endpoint/windows_ad_short_lived_server_object.yml @@ -0,0 +1,77 @@ +name: Windows AD Short Lived Server Object +id: 193769d3-1e33-43a9-970e-ad4a88256cdb +version: 1 +date: '2022-10-17' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: 'The following analytic identifies a change in an Active Directory environment that could represent evidence of the DCShadow attack. + DCShadow allows an attacker who has obtained privileged access to register a rogue Domain Controller (DC). Once registered, the rogue DC may be able to inject + and replicate changes in the AD infrastructure for any domain object, including credentials and keys. This technique was initially released in 2018 by security + researchers Benjamin Delpy and Vincent Le Toux. Specifically, the detection will trigger when a possible rogue Domain Controller + computer object is created and quickly deleted within 30 seconds or less in an Active Directory domain. This behavior was identfied by simulating the DCShadow attack with + Mimikatz.' +search: ' `wineventlog_security` EventCode=5137 OR EventCode=5141 ObjectDN="*CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration*" + | transaction ObjectDN startswith=(EventCode=5137) endswith=(EventCode=5141) + | eval short_lived=case((duration<30),"TRUE") + | search short_lived = TRUE + | stats values(ObjectDN) values(signature) values(EventCode) by _time, Computer, SubjectUserName + | `windows_ad_short_lived_server_object_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting Event codes + `5137` and `5141`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. For these event codes to be generated, specific SACLs are required. +known_false_positives: Creating and deleting a server object within 30 seconds or less is unusual but not impossible in a production environment. Filter as needed. +references: +- https://www.dcshadow.com/ +- https://attack.mitre.org/techniques/T1207/ +- https://stealthbits.com/blog/detecting-dcshadow-with-event-logs/ +- https://pentestlab.blog/2018/04/16/dcshadow/ +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5137 +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5141 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + - Stage:Privilege Escalation + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/short_lived_server_object/windows-security.log + impact: 80 + kill_chain_phases: + - Installation + - Actions on Objectives + message: Potential DCShadow Attack Detected on $Computer$ + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: Computer + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectDN + - signature + - SubjectUserName + - Computer + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml new file mode 100644 index 0000000000..d87b775222 --- /dev/null +++ b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml @@ -0,0 +1,66 @@ +name: Windows AD SID History Attribute Modified +id: 1155e47d-307f-4247-beab-71071e3a458c +version: 1 +date: '2022-11-16' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic leverages event code `5136` to identify a modification of the SID History AD attribute. + The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access + continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries to stealthily grant access to a backdoor account within the same domain. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=sIDHistory OperationType="%%14674" + | stats values(ObjectDN) by _time, Computer, SubjectUserName, AttributeValue + | `windows_ad_sid_history_attribute_modified_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications. +known_false_positives: Domain mergers and migrations may generate large volumes of false positives for this analytic. +references: +- https://adsecurity.org/?p=1772 +- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN +- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute +- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/sid_history2/windows-security.log + impact: 80 + kill_chain_phases: + - Installation + - Actions on Objectives + message: SID History AD attribute modified by $SubjectUserName$ for $ObjectDN$ + mitre_attack_id: + - T1134 + - T1134.005 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AttributeLDAPDisplayName + - OperationType= + - ObjectDN + - Computer + - SubjectUserName + - AttributeValue + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml b/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml index 46d579f45e..e3ab45ab81 100644 --- a/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml +++ b/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml @@ -1,18 +1,14 @@ name: Windows Disable Windows Group Policy Features Through Registry id: 63a449ae-9f04-11ec-945e-acde48001122 -version: 2 +version: 3 date: '2022-11-14' author: Steven Dick, Teoderick Contreras, Splunk type: Anomaly datamodel: - Endpoint -description: This analytic is to detect a suspicious registry modification to disable - windows features. These techniques are seen in several ransomware malware to impair - the compromised host to make it hard for analyst to mitigate or response from the - attack. Disabling these known features make the analysis and forensic response more - hard. Disabling these feature is not so common but can still be implemented by the - administrator for security purposes. In this scenario filters for users that are - allowed doing this is needed. +description: The following analytic detects a suspicious registry modification used to disable + windows features. This technique has been identified in several ransomware malware families to impair + the compromised host and make it harder for analysts to mitigate or respond to an attack. search: '| tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime FROM datamodel=Endpoint.Processes BY _time span=1h Processes.user Processes.process_id Processes.process_name Processes.process Processes.process_path Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` | join process_guid [ @@ -27,7 +23,8 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709 -known_false_positives: unknown +known_false_positives: Disabling these features for legitimate purposes is not a common use case but can still be implemented by the + administrators. Filter as needed. references: - https://hybrid-analysis.com/sample/ef1c427394c205580576d18ba68d5911089c7da0386f19d1ca126929d3e671ab?environmentId=120&lang=en - https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Krotten-N/detailed-analysis @@ -37,6 +34,7 @@ tags: - Ransomware - Windows Defense Evasion Tactics - Windows Registry Abuse + - Sneaky Active Directory Persistence Tricks dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log kill_chain_phases: diff --git a/detections/endpoint/windows_driver_load_non_standard_path.yml b/detections/endpoint/windows_driver_load_non_standard_path.yml index 066c0483a5..7d8bdb9b97 100644 --- a/detections/endpoint/windows_driver_load_non_standard_path.yml +++ b/detections/endpoint/windows_driver_load_non_standard_path.yml @@ -1,15 +1,15 @@ name: Windows Driver Load Non-Standard Path id: 9216ef3d-066a-4958-8f27-c84589465e62 -version: 1 -date: '2022-04-04' +version: 2 +date: '2023-02-24' author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: The following analytic uses Windows EventCode 7045 to identify new Kernel Mode Drivers being loaded in Windows from a non-standard path. +description: The following analytic uses Windows XML EventCode 7045 to identify new Kernel Mode Drivers being loaded in Windows from a non-standard path. Note that, adversaries may move malicious or vulnerable drivers into these paths and load up. The idea is that this analytic provides visibility into drivers loading in non-standard file paths. -search: '`wineventlog_system` EventCode=7045 Service_Type="kernel mode driver" NOT (Service_File_Name IN ("*\\Windows\\*", "*\\Program File*", "*\\systemroot\\*","%SystemRoot%*", "system32\*")) - | stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode Service_File_Name Service_Name Service_Start_Type Service_Type +search: '`wineventlog_system` EventCode=7045 ServiceType="kernel mode driver" NOT (ImagePath IN ("*\\Windows\\*", "*\\Program File*", "*\\systemroot\\*","%SystemRoot%*", "system32\*")) + | stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ImagePath ServiceName ServiceType | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_driver_load_non_standard_path_filter`' @@ -34,13 +34,14 @@ tags: - Source:Endpoint - Stage:Persistence dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/7045_kerneldrivers.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/xml7045_windows-system.log impact: 60 kill_chain_phases: - Installation message: A kernel mode driver was loaded from a non-standard path on $ComputerName$. mitre_attack_id: - T1014 + - T1068 nist: - DE.CM observable: @@ -53,11 +54,11 @@ tags: - Splunk Enterprise Security - Splunk Cloud required_fields: - - ComputerName + - _time + - Computer - EventCode - - Service_File_Name - - Service_Name - - Service_Start_Type - - Service_Type + - ImagePath + - ServiceName + - ServiceType risk_score: 36 security_domain: endpoint diff --git a/detections/endpoint/windows_mimikatz_crypto_export_file_extensions.yml b/detections/endpoint/windows_mimikatz_crypto_export_file_extensions.yml index 7ddcaa92a2..dd85b2f0b0 100644 --- a/detections/endpoint/windows_mimikatz_crypto_export_file_extensions.yml +++ b/detections/endpoint/windows_mimikatz_crypto_export_file_extensions.yml @@ -6,7 +6,7 @@ author: Michael Haag, Splunk type: Anomaly datamodel: - Endpoint -description: The following analytic identifies hardcoded extensions related to the Crypo module within Mimikatz. Moving certificates or downloading them is not malicious, however with Mimikatz having hardcoded names it helps to identify potential usage of certificates being exported. +description: The following analytic identifies hardcoded extensions related to the Crypto module within Mimikatz. Moving certificates or downloading them is not malicious, however with Mimikatz having hardcoded names it helps to identify potential usage of certificates being exported. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.keyx.rsa.pvk","*sign.rsa.pvk","*sign.dsa.pvk","*dsa.ec.p8k","*dh.ec.p8k", "*.pfx", "*.der") by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Filesystem)` | `windows_mimikatz_crypto_export_file_extensions_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. diff --git a/detections/endpoint/windows_process_injection_into_notepad.yml b/detections/endpoint/windows_process_injection_into_notepad.yml new file mode 100644 index 0000000000..88e8c3f10e --- /dev/null +++ b/detections/endpoint/windows_process_injection_into_notepad.yml @@ -0,0 +1,74 @@ +name: Windows Process Injection into Notepad +id: b8340d0f-ba48-4391-bea7-9e793c5aae36 +version: 1 +date: '2023-02-22' +author: Michael Haag, Splunk +type: Anomaly +datamodel: [] +description: The following analytic utilizes Sysmon to identify process injection into Notepad.exe, based on GrantedAccess requests - 0x40 and 0x1fffff. This particular behavior is attributed to the defaults of the SliverC2 framework by BishopFox. + By default, the analytic filters out any SourceImage paths of System32, Syswow64 and program files. Add more as needed, or remove and monitor what is consistently injecting into notepad.exe. + This particular behavior will occur from a source image that is the initial payload dropped. +search: '`sysmon` EventCode=10 TargetImage IN (*\\notepad.exe) NOT (SourceImage IN ("*\\system32\\*","*\\syswow64\\*","*\\Program Files\\*")) GrantedAccess IN ("0x40","0x1fffff") | stats count min(_time) as firstTime max(_time) as lastTime by dest SourceImage TargetImage GrantedAccess CallTrace + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_process_injection_into_notepad_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: False positives may be present based on SourceImage paths. If removing the paths is important, realize svchost and many native binaries inject into notepad consistently. Restrict or tune as needed. +references: +- https://dominicbreuker.com/post/learning_sliver_c2_08_implant_basics/ +- https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors +tags: + analytic_story: + - BishopFox Sliver Adversary Emulation Framework + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/T1055_windows-sysmon.log + impact: 40 + kill_chain_phases: + - Exploitation + message: An instance of $SourceImage$ injecting into $TargetImage$ was identified on endpoint $dest$. + mitre_attack_id: + - T1055 + - T1055.002 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: SourceImage + type: Process + role: + - Parent Process + - name: TargetImage + type: Process + role: + - Child Process + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - SourceImage + - TargetImage + - GrantedAccess + - CallTrace + risk_score: 32 + security_domain: endpoint \ No newline at end of file diff --git a/detections/endpoint/windows_security_support_provider_reg_query.yml b/detections/endpoint/windows_security_support_provider_reg_query.yml index 967b7ea5c0..5efe828ec5 100644 --- a/detections/endpoint/windows_security_support_provider_reg_query.yml +++ b/detections/endpoint/windows_security_support_provider_reg_query.yml @@ -32,6 +32,7 @@ tags: analytic_story: - Windows Post-Exploitation - Prestige Ransomware + - Sneaky Active Directory Persistence Tricks asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/endpoint/windows_service_create_sliverc2.yml b/detections/endpoint/windows_service_create_sliverc2.yml new file mode 100644 index 0000000000..eaf0689cea --- /dev/null +++ b/detections/endpoint/windows_service_create_sliverc2.yml @@ -0,0 +1,55 @@ +name: Windows Service Create SliverC2 +id: 89dad3ee-57ec-43dc-9044-131c4edd663f +version: 1 +date: '2023-03-03' +author: Michael Haag, Splunk +type: TTP +datamodel: [] +description: When an adversary utilizes SliverC2 to laterally move with the Psexec module, it will create a service with the name and description of "Sliver" and "Sliver Implant". Note that these may be easily changed and are specific to only SliverC2. + We have also created the same regex as Microsoft has outlined to attempt to capture the suspicious service path (regex101 reference). +search: '`wineventlog_system` EventCode=7045 ServiceName="sliver" + | stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode ImagePath ServiceName ServiceType + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `windows_service_create_sliverc2_filter`' +how_to_implement: To implement this analytic, the Windows EventCode 7045 will need to be logged from the System Event log. The Windows TA for Splunk is also recommended. +known_false_positives: False positives should be limited, but if another service out there is named Sliver, filtering may be needed. +references: + - https://github.com/BishopFox/sliver/blob/71f94928bf36c1557ea5fbeffa161b71116f56b2/client/command/exec/psexec.go#LL61C5-L61C16 + - https://www.microsoft.com/en-us/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/ + - https://regex101.com/r/DWkkXm/1 +tags: + analytic_story: + - BishopFox Sliver Adversary Emulation Framework + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 100 + context: + - Source:Endpoint + - Stage:Lateral Movement + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/sliver_windows-system.log + impact: 90 + kill_chain_phases: + - Installation + message: A user mode service was created on $ComputerName$ related to SliverC2. + mitre_attack_id: + - T1569 + - T1569.002 + nist: + - DE.CM + observable: + - name: ComputerName + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - UPDATE + risk_score: 90 + security_domain: endpoint \ No newline at end of file diff --git a/detections/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml b/detections/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml new file mode 100644 index 0000000000..a40e4e2f62 --- /dev/null +++ b/detections/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml @@ -0,0 +1,64 @@ +name: Windows AD Domain Controller Audit Policy Disabled +id: fc3ccef1-60a4-4239-bd66-b279511b4d14 +version: 1 +date: '2023-01-26' +author: Dean Luxton +type: TTP +datamodel: [] +description: This analytic looks for audit policies being disabled on a domain controller. +search: '`wineventlog_security` EventCode=4719 (AuditPolicyChanges IN ("%%8448","%%8450","%%8448, + %%8450") OR Changes IN ("Failure removed","Success removed","Success removed, Failure + removed")) dest_category="domain_controller" + + | replace "%%8448" with "Success removed", "%%8450" with "Failure removed", "%%8448, + %%8450" with "Success removed, Failure removed" in AuditPolicyChanges + + | eval AuditPolicyChanges=coalesce(AuditPolicyChanges,Changes), SubcategoryGuid=coalesce(SubcategoryGuid,Subcategory_GUID) + + | stats min(_time) as _time values(host) as dest by AuditPolicyChanges SubcategoryGuid + + | lookup advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory + | `windows_ad_domain_controller_audit_policy_disabled_filter`' +how_to_implement: Ensure you are ingesting EventCode `4719` from your domain controllers, the category domain_controller exists + in assets and identities, and that assets and identities is enabled. If A&I is not configured, you will need to manually filter the results + within the base search. +known_false_positives: Unknown +references: +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4719 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 60 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_gpo/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: GPO $SubCategory$ of $Category$ was disabled on $dest$ + mitre_attack_id: + - T1562.001 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AuditPolicyChanges + - SubcategoryGuid + risk_score: 60 + security_domain: endpoint diff --git a/detections/experimental/endpoint/windows_ad_domain_replication_acl_addition.yml b/detections/experimental/endpoint/windows_ad_domain_replication_acl_addition.yml new file mode 100644 index 0000000000..ff73722cfc --- /dev/null +++ b/detections/experimental/endpoint/windows_ad_domain_replication_acl_addition.yml @@ -0,0 +1,89 @@ +name: Windows AD Domain Replication ACL Addition +id: 8c372853-f459-4995-afdc-280c114d33ab +version: 1 +date: '2022-11-18' +author: Dean Luxton +type: TTP +datamodel: [] +description: This analytic detects the addition of the permissions necessary to perform a DCSync attack. + In order to replicate AD objects, the initiating user or computer must have the following permissions on the domain. + - DS-Replication-Get-Changes + - DS-Replication-Get-Changes-All + Certain Sync operations may require the additional permission of DS-Replication-Get-Changes-In-Filtered-Set. + By default, adding DCSync permissions via the Powerview Add-ObjectACL operation adds all 3. This alert identifies where this trifecta has been met, and also where just the base level requirements have been met. +search: "`wineventlog_security` (EventCode=5136) AttributeLDAPDisplayName=\"ntSecurityDescriptor\"\ + \ \"1131f6ad-9c07-11d1-f79f-00c04fc2dcd2\" OR \"1131f6aa-9c07-11d1-f79f-00c04fc2dcd2\"\ + \ OR \"89e95b76-444d-4c62-991a-0facbeda640c\" \n| where AttributeValue like \"%1131f6ad-9c07-11d1-f79f-00c04fc2dcd2%\"\ + \ AND AttributeValue like \"%1131f6aa-9c07-11d1-f79f-00c04fc2dcd2%\" AND AttributeValue\ + \ like \"%89e95b76-444d-4c62-991a-0facbeda640c%\" \n| search NOT ObjectClass IN\ + \ (dnsNode,dnsZoneScope,dnsZone)\n| rex field=AttributeValue max_match=10000 \"\ + OA;;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;(?PS-1-[0-59]-\\\ + d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| rex field=AttributeValue\ + \ max_match=10000 \"OA;;CR;1131f6ad-9c07-11d1-f79f-00c04fc2dcd2;;(?PS-1-[0-59]-\\\ + d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| rex field=AttributeValue\ + \ max_match=10000 \"OA;;CR;89e95b76-444d-4c62-991a-0facbeda640c;;(?PS-1-[0-59]-\\\ + d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| table _time dest src_user DSRGetChanges_user_sid\ + \ DSRGetChangesAll_user_sid DSRGetChangesFiltered_user_sid\n| mvexpand DSRGetChanges_user_sid\n\ + | eval minDCSyncPermissions=if(DSRGetChanges_user_sid=DSRGetChangesAll_user_sid,\"\ + true\",\"false\"), fullSet=if(DSRGetChanges_user_sid=DSRGetChangesAll_user_sid AND\ + \ DSRGetChanges_user_sid=DSRGetChangesFiltered_user_sid,\"true\",\"false\")\n| where\ + \ minDCSyncPermissions=\"true\"\n| lookup identity_lookup_expanded objectSid as\ + \ DSRGetChanges_user_sid OUTPUT sAMAccountName as user\n| rename DSRGetChanges_user_sid\ + \ as userSid\n| stats min(_time) as _time values(user) as user by dest src_user userSid minDCSyncPermissions fullSet|\ + \ `windows_ad_domain_replication_acl_addition_filter`" +how_to_implement: To successfully implement this search, you need to be ingesting the eventcode 5136. The Advanced Security Audit policy setting + `Audit Directory Services Changes` within `DS Access` needs to be enabled, alongside a SACL for `everybody` to `Write All Properties` + applied to the domain root and all descendant objects. Once the necessary logging has been enabled, enumerate the domain policy to verify if existing + accounts with access need to be whitelisted, or revoked. Assets and Identities is also leveraged to automatically translate the objectSid into username. + Ensure your identities lookup is configured with the sAMAccountName and objectSid of all AD user and computer objects. +known_false_positives: When there is a change to nTSecurityDescriptor, Windows logs the entire ACL with the newly added components. + If existing accounts are present with this permission, they will raise an alert each time the nTSecurityDescriptor is updated unless whitelisted. +references: +- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/1522b774-6464-41a3-87a5-1e5633c3fbbb +- https://github.com/SigmaHQ/sigma/blob/29a5c62784faf986dc03952ae3e90e3df3294284/rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 6 + confidence: 80 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/aclmodification/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: $src_user$ has granted $user$ permission to replicate AD objects + mitre_attack_id: + - T1484 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - src_user + - AttributeLDAPDisplayName + - AttributeValue + - ObjectClass + risk_score: 80 + security_domain: endpoint diff --git a/detections/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.yml b/detections/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.yml new file mode 100644 index 0000000000..1b3c5a3f25 --- /dev/null +++ b/detections/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.yml @@ -0,0 +1,77 @@ +name: Windows AD Privileged Account SID History Addition +id: 6b521149-b91c-43aa-ba97-c2cac59ec830 +version: 1 +date: '2022-09-12' +author: Dean Luxton +type: TTP +datamodel: [] +description: This detection identifies when the SID of a privileged user is added to + the SID History attribute of another user. Useful for tracking SID history abuse + across multiple domains. This detection leverages the Asset and Identities + framework. See the implementation section for further details on configuration. +search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory IN ("%%1793", -) + | rex field=SidHistory "(^%{|^)(?P.*?)(}$|$)" + | eval category="privileged" + | lookup identity_lookup_expanded category, identity as SidHistory OUTPUT identity_tag as match + | where isnotnull(match) + | rename TargetSid as userSid + | table _time action status host user userSid SidHistory Logon_ID src_user + | `windows_active_directory_privileged_account_sid_history_addition_filter`' +how_to_implement: Ensure you have objectSid and the Down Level Logon Name `DOMAIN\sAMACountName` + added to the identity field of your Asset and Identities lookup, along with the + category of privileged for the applicable users. Ensure you are + ingesting eventcodes 4742 and 4738. Two advanced audit policies + `Audit User Account Management` and `Audit Computer Account Management` under + `Account Management` are required to generate these event codes. +known_false_positives: Migration of privileged accounts. +references: +- https://adsecurity.org/?p=1772 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + - CIS 16 + confidence: 90 + context: + - Source:Endpoint + - Source:AD + - Stage:Defense Evasion + - Stage:Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: A Privileged User Account SID History Attribute was added to $user$ by $src_user$ + mitre_attack_id: + - T1134.005 + - T1134 + nist: + - DE.CM + observable: + - name: src_user + type: User + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - SidHistory + - TargetSid + - TargetDomainName + - user + - src_user + - Logon_ID + risk_score: 90 + security_domain: endpoint diff --git a/detections/experimental/network/windows_ad_replication_service_traffic.yml b/detections/experimental/network/windows_ad_replication_service_traffic.yml new file mode 100644 index 0000000000..3d862b148d --- /dev/null +++ b/detections/experimental/network/windows_ad_replication_service_traffic.yml @@ -0,0 +1,72 @@ +name: Windows AD Replication Service Traffic +id: c6e24183-a5f4-4b2a-ad01-2eb456d09b67 +version: 1 +date: '2022-11-26' +author: Steven Dick +type: TTP +datamodel: +- Network_Traffic +- Network_Sessions +description: This search looks for evidence of Active Directory replication traffic [MS-DRSR] from unexpected sources. + This traffic is often seen exclusively between Domain Controllers for AD database replication. + Any detections from non-domain controller source to a domain controller may indicate the usage of DCSync or DCShadow credential dumping techniques. +search: ' | tstats `security_content_summariesonly` count values(All_Traffic.transport) as transport values(All_Traffic.user) as user + values(All_Traffic.src_category) as src_category values(All_Traffic.dest_category) as dest_category min(_time) as firstTime max(_time) as lastTime + from datamodel=Network_Traffic where All_Traffic.app IN ("ms-dc-replication","*drsr*","ad drs") by All_Traffic.src All_Traffic.dest All_Traffic.app + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `drop_dm_object_name("All_Traffic")` + | `active_directory_replication_traffic_from_unknown_source_filter` + | `windows_ad_replication_service_traffic_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + application aware firewall or proxy logs into the Network Datamodel. Categorize + all known domain controller Assets servers with an appropriate category for filtering. +known_false_positives: New domain controllers or certian scripts run by administrators. +references: +- https://adsecurity.org/?p=1729 +- https://attack.mitre.org/techniques/T1003/006/ +- https://attack.mitre.org/techniques/T1207/ +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 100 + context: + - Source:Endpoint + - Stage:Credential Access + dataset: + - UPDATE_DATASET_URL + impact: 100 + kill_chain_phases: + - Exploitation + - Actions on Objectives + message: Active Directory Replication Traffic from Unknown Source - $src$ + mitre_attack_id: + - T1003 + - T1003.006 + - T1207 + nist: + - DE.CM + observable: + - name: dest + type: IP Address + role: + - Victim + - name: src + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - All_Traffic.src + - All_Traffic.dest + - All_Traffic.app + risk_score: 100 + security_domain: network diff --git a/detections/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml b/detections/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml new file mode 100644 index 0000000000..fb8a711cbd --- /dev/null +++ b/detections/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml @@ -0,0 +1,57 @@ +name: Windows AD Rogue Domain Controller Network Activity +id: c4aeeeef-da7f-4338-b3ba-553cbcbe2138 +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: [] +description: This detection is looking at zeek wiredata for specific replication RPC calls being performed from a device which is not a domain controller. + If you would like to capture these RPC calls using Splunk Stream, please vote for my idea here https://ideas.splunk.com/ideas/APPSID-I-619 ;) +search: '`zeek_rpc` DrsReplicaAdd OR DRSGetNCChanges + | where NOT (dest_category="Domain Controller") OR NOT (src_category="Domain Controller") + | fillnull value="Unknown" src_category, dest_category + | table _time endpoint operation src src_category dest dest_category | `rogue_dc_network_activity_filter`' +how_to_implement: Run zeek on domain controllers to capture the DCE RPC calls, ensure the domain controller categories are defined in Assets and Identities. +known_false_positives: None. +references: +- https://adsecurity.org/?p=1729 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:IPS + - Stage:Defense Evasion + dataset: + - https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1207/mimikatz/zeek-dce_rpc.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Rogue DC Activity Detected from $src_category$ device $src$ to $dest$ ($dest_category$) + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: src + type: IP Address + role: + - Attacker + - name: dest + type: IP Address + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - src + - dest + risk_score: 100 + security_domain: network diff --git a/lookups/advanced_audit_policy_guids.csv b/lookups/advanced_audit_policy_guids.csv new file mode 100644 index 0000000000..646c8914a8 --- /dev/null +++ b/lookups/advanced_audit_policy_guids.csv @@ -0,0 +1,69 @@ +Category,SubCategory,GUID +System,,{69979848-797A-11D9-BED3-505054503030} +System,Security State Change,{0CCE9210-69AE-11D9-BED3-505054503030} +System,Security System Extension,{0CCE9211-69AE-11D9-BED3-505054503030} +System,System Integrity,{0CCE9212-69AE-11D9-BED3-505054503030} +System,IPsec Driver,{0CCE9213-69AE-11D9-BED3-505054503030} +System,Other System Events,{0CCE9214-69AE-11D9-BED3-505054503030} +Logon/Logoff,,{69979849-797A-11D9-BED3-505054503030} +Logon/Logoff,Logon,{0CCE9215-69AE-11D9-BED3-505054503030} +Logon/Logoff,Logoff,{0CCE9216-69AE-11D9-BED3-505054503030} +Logon/Logoff,Account Lockout,{0CCE9217-69AE-11D9-BED3-505054503030} +Logon/Logoff,IPsec Main Mode,{0CCE9218-69AE-11D9-BED3-505054503030} +Logon/Logoff,IPsec Quick Mode,{0CCE9219-69AE-11D9-BED3-505054503030} +Logon/Logoff,IPsec Extended Mode,{0CCE921A-69AE-11D9-BED3-505054503030} +Logon/Logoff,Special Logon,{0CCE921B-69AE-11D9-BED3-505054503030} +Logon/Logoff,Other Logon/Logoff Events,{0CCE921C-69AE-11D9-BED3-505054503030} +Logon/Logoff,Network Policy Server,{0CCE9243-69AE-11D9-BED3-505054503030} +Logon/Logoff,User / Device Claims,{0CCE9247-69AE-11D9-BED3-505054503030} +Logon/Logoff,Group Membership,{0CCE9249-69AE-11D9-BED3-505054503030} +Object Access,,{6997984A-797A-11D9-BED3-505054503030} +Object Access,File System,{0CCE921D-69AE-11D9-BED3-505054503030} +Object Access,Registry,{0CCE921E-69AE-11D9-BED3-505054503030} +Object Access,Kernel Object,{0CCE921F-69AE-11D9-BED3-505054503030} +Object Access,SAM,{0CCE9220-69AE-11D9-BED3-505054503030} +Object Access,Certification Services,{0CCE9221-69AE-11D9-BED3-505054503030} +Object Access,Application Generated,{0CCE9222-69AE-11D9-BED3-505054503030} +Object Access,Handle Manipulation,{0CCE9223-69AE-11D9-BED3-505054503030} +Object Access,File Share,{0CCE9224-69AE-11D9-BED3-505054503030} +Object Access,Filtering Platform Packet Drop,{0CCE9225-69AE-11D9-BED3-505054503030} +Object Access,Filtering Platform Connection,{0CCE9226-69AE-11D9-BED3-505054503030} +Object Access,Other Object Access Events,{0CCE9227-69AE-11D9-BED3-505054503030} +Object Access,Detailed File Share,{0CCE9244-69AE-11D9-BED3-505054503030} +Object Access,Removable Storage,{0CCE9245-69AE-11D9-BED3-505054503030} +Object Access,Central Policy Staging,{0CCE9246-69AE-11D9-BED3-505054503030} +Privilege Use,,{6997984B-797A-11D9-BED3-505054503030} +Privilege Use,Sensitive Privilege Use,{0CCE9228-69AE-11D9-BED3-505054503030} +Privilege Use,Non Sensitive Privilege Use,{0CCE9229-69AE-11D9-BED3-505054503030} +Privilege Use,Other Privilege Use Events,{0CCE922A-69AE-11D9-BED3-505054503030} +Detailed Tracking,,{6997984C-797A-11D9-BED3-505054503030} +Detailed Tracking,Process Creation,{0CCE922B-69AE-11D9-BED3-505054503030} +Detailed Tracking,Process Termination,{0CCE922C-69AE-11D9-BED3-505054503030} +Detailed Tracking,DPAPI Activity,{0CCE922D-69AE-11D9-BED3-505054503030} +Detailed Tracking,RPC Events,{0CCE922E-69AE-11D9-BED3-505054503030} +Detailed Tracking,Plug and Play Events,{0CCE9248-69AE-11D9-BED3-505054503030} +Detailed Tracking,Token Right Adjusted Events,{0CCE924A-69AE-11D9-BED3-505054503030} +Policy Change,,{6997984D-797A-11D9-BED3-505054503030} +Policy Change,Audit Policy Change,{0CCE922F-69AE-11D9-BED3-505054503030} +Policy Change,Authentication Policy Change,{0CCE9230-69AE-11D9-BED3-505054503030} +Policy Change,Authorization Policy Change,{0CCE9231-69AE-11D9-BED3-505054503030} +Policy Change,MPSSVC Rule-Level Policy Change,{0CCE9232-69AE-11D9-BED3-505054503030} +Policy Change,Filtering Platform Policy Change,{0CCE9233-69AE-11D9-BED3-505054503030} +Policy Change,Other Policy Change Events,{0CCE9234-69AE-11D9-BED3-505054503030} +Account Management,,{6997984E-797A-11D9-BED3-505054503030} +Account Management,User Account Management,{0CCE9235-69AE-11D9-BED3-505054503030} +Account Management,Computer Account Management,{0CCE9236-69AE-11D9-BED3-505054503030} +Account Management,Security Group Management,{0CCE9237-69AE-11D9-BED3-505054503030} +Account Management,Distribution Group Management,{0CCE9238-69AE-11D9-BED3-505054503030} +Account Management,Application Group Management,{0CCE9239-69AE-11D9-BED3-505054503030} +Account Management,Other Account Management Events,{0CCE923A-69AE-11D9-BED3-505054503030} +DS Access,,{6997984F-797A-11D9-BED3-505054503030} +DS Access,Directory Service Access,{0CCE923B-69AE-11D9-BED3-505054503030} +DS Access,Directory Service Changes,{0CCE923C-69AE-11D9-BED3-505054503030} +DS Access,Directory Service Replication,{0CCE923D-69AE-11D9-BED3-505054503030} +DS Access,Detailed Directory Service Replication,{0CCE923E-69AE-11D9-BED3-505054503030} +Account Logon,,{69979850-797A-11D9-BED3-505054503030} +Account Logon,Credential Validation,{0CCE923F-69AE-11D9-BED3-505054503030} +Account Logon,Kerberos Service Ticket Operations,{0CCE9240-69AE-11D9-BED3-505054503030} +Account Logon,Other Account Logon Events,{0CCE9241-69AE-11D9-BED3-505054503030} +Account Logon,Kerberos Authentication Service,{0CCE9242-69AE-11D9-BED3-505054503030} \ No newline at end of file diff --git a/lookups/advanced_audit_policy_guids.yml b/lookups/advanced_audit_policy_guids.yml new file mode 100644 index 0000000000..37b6e854af --- /dev/null +++ b/lookups/advanced_audit_policy_guids.yml @@ -0,0 +1,7 @@ +description: List of GUIDs associated with Windows advanced audit policies +filename: advanced_audit_policy_guids.csv +name: advanced_audit_policy_guids +default_match: 'false' +match_type: WILDCARD(GUID) +min_matches: 1 +case_sensitive_match: 'false' \ No newline at end of file diff --git a/macros/wineventlog_security.yml b/macros/wineventlog_security.yml index cfbe346e92..65bed12450 100644 --- a/macros/wineventlog_security.yml +++ b/macros/wineventlog_security.yml @@ -1,4 +1,4 @@ -definition: eventtype=wineventlog_security OR source="XmlWinEventLog:Security" +definition: eventtype=wineventlog_security OR Channel=security OR source=XmlWinEventLog:Security description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. name: wineventlog_security diff --git a/stories/bishopfox_sliver_adversary_emulation_framework.yml b/stories/bishopfox_sliver_adversary_emulation_framework.yml new file mode 100644 index 0000000000..a8531255aa --- /dev/null +++ b/stories/bishopfox_sliver_adversary_emulation_framework.yml @@ -0,0 +1,23 @@ +name: BishopFox Sliver Adversary Emulation Framework +id: 8c2e2cba-3fd8-424f-a890-5080bdaf3f31 +version: 1 +date: '2023-01-24' +author: Michael Haag, Splunk +description: The following analytic story providers visibility into the latest adversary TTPs in regard to the use of Sliver. Sliver has gained more traction with adversaries as it is often seen as an alternative to Cobalt Strike. It is designed to be scalable and can be used by organizations of all sizes to perform security testing. Sliver is highly modular and contains an Extension package manager (armory) allowing easy install (automatic compilation) of various 3rd party tools such as BOFs and .NET tooling like Ghostpack (Rubeus, Seatbelt, SharpUp, Certify, and so forth) (CyberReason,2023). +narrative: Sliver is an open source cross-platform adversary emulation/red team framework produced by BishopFox. +references: + - https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors + - https://www.ncsc.gov.uk/files/Advisory%20Further%20TTPs%20associated%20with%20SVR%20cyber%20actors.pdf + - https://www.proofpoint.com/uk/blog/security-briefs/ta551-uses-sliver-red-team-tool-new-activity + - https://www.cybereason.com/blog/threat-analysis-report-bumblebee-loader-the-high-road-to-enterprise-domain-control + - https://github.com/sliverarmory/armory + - https://github.com/BishopFox/sliver +tags: + analytic_story: BishopFox Sliver Adversary Emulation Framework + category: + - Adversary Tactics + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection diff --git a/stories/sneaky_active_directory_persistence_tricks.yml b/stories/sneaky_active_directory_persistence_tricks.yml new file mode 100644 index 0000000000..3b579b4f9a --- /dev/null +++ b/stories/sneaky_active_directory_persistence_tricks.yml @@ -0,0 +1,37 @@ +name: Sneaky Active Directory Persistence Tricks +id: f676c4c1-c769-4ecb-9611-5fd85b497c56 +version: 1 +date: '2022-08-29' +author: Dean Luxton, Mauricio Velazco, Splunk +description: Monitor for activities and techniques associated with Windows Active Directory persistence techniques. +narrative: Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. + Active Directory is a centralized and hierarchical database that stores information about users, computers, and other resources on a network. It provides secure and efficient management + of these resources and enables administrators to enforce security policies and delegate administrative tasks.\ + + In 2015 Active Directory security researcher Sean Metcalf published a blog post titled `Sneaky Active Directory Persistence Tricks`. In this blog post, + Sean described several methods through which an attacker could persist administrative access on an Active Directory network after having Domain Admin level rights for + a short period of time. At the time of writing, 8 years after the initial blog post, most of these techniques are still possible since they abuse legitimate administrative functionality and not software vulnerabilities. + Security engineers defending Active Directory networks should be aware of these technique available to adversaries post exploitation and deploy both preventive and detective security controls for them.\ + + This analytic story groups detection opportunities for most of the techniques described on Seans blog post as well as other high impact attacks against Active Directory networks and Domain Controllers like DCSync and DCShadow. + For some of these detection opportunities, it is necessary to enable the necessary GPOs and SACLs required, otherwise the event codes will not trigger. Each detection includes a list of requirements for enabling logging. +references: + - https://adsecurity.org/?p=1929 + - https://www.youtube.com/watch?v=Lz6haohGAMc&feature=youtu.be + - https://adsecurity.org/wp-content/uploads/2015/09/DEFCON23-2015-Metcalf-RedvsBlue-ADAttackAndDefense-Final.pdf + - https://attack.mitre.org/tactics/TA0003/ + - https://www.dcshadow.com + - https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2 + - https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer +tags: + analytic_story: Windows Domain Controller Attacks + category: + - Adversary Tactics + - Account Compromise + - Lateral Movement + - Privilege Escalation + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection diff --git a/tests/endpoint/disabling_windows_local_security_authority_defences_via_registry.test.yml b/tests/endpoint/disabling_windows_local_security_authority_defences_via_registry.test.yml new file mode 100644 index 0000000000..4ca8e90ad4 --- /dev/null +++ b/tests/endpoint/disabling_windows_local_security_authority_defences_via_registry.test.yml @@ -0,0 +1,13 @@ +name: Disabling Windows Local Security Authority Defences via Registry Unit Test +tests: +- name: Disabling Windows Local Security Authority Defences via Registry + file: endpoint/disabling_windows_local_security_authority_defences_via_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_lsa_protection/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/notepad_with_no_command_line_arguments.test.yml b/tests/endpoint/notepad_with_no_command_line_arguments.test.yml new file mode 100644 index 0000000000..95a87b12b0 --- /dev/null +++ b/tests/endpoint/notepad_with_no_command_line_arguments.test.yml @@ -0,0 +1,13 @@ +name: Notepad with no Command Line Arguments Unit Test +tests: +- name: Notepad with no Command Line Arguments + file: endpoint/notepad_with_no_command_line_arguments.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: notepad_windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/notepad_windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_adminsdholder_acl_modified.test.yml b/tests/endpoint/windows_ad_adminsdholder_acl_modified.test.yml new file mode 100644 index 0000000000..8648fa463e --- /dev/null +++ b/tests/endpoint/windows_ad_adminsdholder_acl_modified.test.yml @@ -0,0 +1,13 @@ +name: Windows AD AdminSDHolder ACL Modified Unit Test +tests: +- name: Windows AD AdminSDHolder ACL Modified + file: endpoint/windows_ad_adminsdholder_acl_modified.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/adminsdholder_modified/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_cross_domain_sid_history_addition.test.yml b/tests/endpoint/windows_ad_cross_domain_sid_history_addition.test.yml new file mode 100644 index 0000000000..834dc84db9 --- /dev/null +++ b/tests/endpoint/windows_ad_cross_domain_sid_history_addition.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Cross Domain SID History Addition Unit Test +tests: +- name: Windows AD Cross Domain SID History Addition + file: endpoint/windows_ad_cross_domain_sid_history_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true \ No newline at end of file diff --git a/tests/endpoint/windows_ad_domain_controller_promotion.test.yml b/tests/endpoint/windows_ad_domain_controller_promotion.test.yml new file mode 100644 index 0000000000..277852be84 --- /dev/null +++ b/tests/endpoint/windows_ad_domain_controller_promotion.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Domain Controller Promotion Unit Test +tests: +- name: Windows AD Domain Controller Promotion + file: endpoint/windows_ad_domain_controller_promotion.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/dc_promo/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_dsrm_account_changes.test.yml b/tests/endpoint/windows_ad_dsrm_account_changes.test.yml new file mode 100644 index 0000000000..4cb26cc417 --- /dev/null +++ b/tests/endpoint/windows_ad_dsrm_account_changes.test.yml @@ -0,0 +1,13 @@ +name: Windows AD DSRM Account Changes Unit Test +tests: +- name: Windows AD DSRM Account Changes + file: endpoint/windows_ad_dsrm_account_changes.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_dsrm_password_reset.test.yml b/tests/endpoint/windows_ad_dsrm_password_reset.test.yml new file mode 100644 index 0000000000..dee73e24ff --- /dev/null +++ b/tests/endpoint/windows_ad_dsrm_password_reset.test.yml @@ -0,0 +1,13 @@ +name: Windows AD DSRM Password Reset Unit Test +tests: +- name: Windows AD DSRM Password Reset + file: endpoint/windows_ad_dsrm_password_reset.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_replication_request_initiated_by_user_account.test.yml b/tests/endpoint/windows_ad_replication_request_initiated_by_user_account.test.yml new file mode 100644 index 0000000000..d9c577236c --- /dev/null +++ b/tests/endpoint/windows_ad_replication_request_initiated_by_user_account.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Replication Request Initiated by User Account Test +tests: +- name: Windows AD Replication Request Initiated by User Account + file: endpoint/windows_ad_replication_request_initiated_by_user_account.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true \ No newline at end of file diff --git a/tests/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.test.yml b/tests/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.test.yml new file mode 100644 index 0000000000..91d9608390 --- /dev/null +++ b/tests/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.test.yml @@ -0,0 +1,14 @@ +name: Windows AD Replication Request Initiated from Unsanctioned Location Test +tests: +- name: Windows AD Replication Request Initiated from Unsanctioned Location + file: endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true + diff --git a/tests/endpoint/windows_ad_same_domain_sid_history_addition.test.yml b/tests/endpoint/windows_ad_same_domain_sid_history_addition.test.yml new file mode 100644 index 0000000000..ffcc53cdcd --- /dev/null +++ b/tests/endpoint/windows_ad_same_domain_sid_history_addition.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Same Domain SID History Addition Unit Test +tests: +- name: Windows AD Same Domain SID History Addition + file: endpoint/windows_ad_same_domain_sid_history_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.test.yml b/tests/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.test.yml new file mode 100644 index 0000000000..71d06d0868 --- /dev/null +++ b/tests/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.test.yml @@ -0,0 +1,13 @@ +name: Windows AD ServicePrincipalName Added To Domain Account Unit Test +tests: +- name: Windows AD ServicePrincipalName Added To Domain Account + file: endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.test.yml b/tests/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.test.yml new file mode 100644 index 0000000000..0e3107989b --- /dev/null +++ b/tests/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Short Lived Domain Account ServicePrincipalName Unit Test +tests: +- name: Windows AD Short Lived Domain Account ServicePrincipalName + file: endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/short_lived_service_principal_name/windows-security.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.test.yml b/tests/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.test.yml new file mode 100644 index 0000000000..4c4617769f --- /dev/null +++ b/tests/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Short Lived Domain Controller SPN Attribute Unit Test +tests: +- name: Windows AD Short Lived Domain Controller SPN Attribute + file: endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/mimikatz/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_short_lived_server_object.test.yml b/tests/endpoint/windows_ad_short_lived_server_object.test.yml new file mode 100644 index 0000000000..0593d3ac4c --- /dev/null +++ b/tests/endpoint/windows_ad_short_lived_server_object.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Short Lived Server Object Unit Test +tests: +- name: Windows Short Lived AD Server Object + file: endpoint/windows_ad_short_lived_server_object.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/short_lived_server_object/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_sid_history_attribute_modified.test.yml b/tests/endpoint/windows_ad_sid_history_attribute_modified.test.yml new file mode 100644 index 0000000000..2809d85fdb --- /dev/null +++ b/tests/endpoint/windows_ad_sid_history_attribute_modified.test.yml @@ -0,0 +1,13 @@ +name: Windows AD SID History Attribute Modified +tests: +- name: Windows AD SID History Attribute Modified + file: endpoint/windows_ad_sid_history_attribute_modified.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/sid_history2/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_driver_load_non_standard_path.test.yml b/tests/endpoint/windows_driver_load_non_standard_path.test.yml index cc7095689b..4fec7cc049 100644 --- a/tests/endpoint/windows_driver_load_non_standard_path.test.yml +++ b/tests/endpoint/windows_driver_load_non_standard_path.test.yml @@ -6,8 +6,8 @@ tests: earliest_time: -24h latest_time: now attack_data: - - file_name: 7045_kerneldrivers.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/7045_kerneldrivers.log - source: WinEventLog:System - sourcetype: WinEventLog + - file_name: xml7045_windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1068/drivers/xml7045_windows-system.log + source: XmlWinEventLog:System + sourcetype: XmlWinEventLog update_timestamp: true \ No newline at end of file diff --git a/tests/endpoint/windows_process_injection_into_notepad.test.yml b/tests/endpoint/windows_process_injection_into_notepad.test.yml new file mode 100644 index 0000000000..acba7a6722 --- /dev/null +++ b/tests/endpoint/windows_process_injection_into_notepad.test.yml @@ -0,0 +1,13 @@ +name: Windows Process Injection into Notepad Unit Test +tests: +- name: Windows Process Injection into Notepad + file: endpoint/windows_process_injection_into_notepad.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: T1055_windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/T1055_windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_service_create_sliverc2.test.yml b/tests/endpoint/windows_service_create_sliverc2.test.yml new file mode 100644 index 0000000000..fae6b890ec --- /dev/null +++ b/tests/endpoint/windows_service_create_sliverc2.test.yml @@ -0,0 +1,13 @@ +name: Windows Service Create SliverC2 Unit Test +tests: +- name: Windows Service Create SliverC2 + file: endpoint/windows_service_create_sliverc2.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: sliver_windows-system.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/sliver_windows-system.log + source: XmlWinEventLog:System + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.test.yml b/tests/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.test.yml new file mode 100644 index 0000000000..ea28d2a0f9 --- /dev/null +++ b/tests/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Domain Controller Audit Policy Disabled Unit Test +tests: +- name: Windows AD Domain Controller Audit Policy Disabled + file: endpoint/windows_ad_domain_controller_audit_policy_disabled.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_gpo/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/experimental/endpoint/windows_ad_domain_replication_acl_addition.test.yml b/tests/experimental/endpoint/windows_ad_domain_replication_acl_addition.test.yml new file mode 100644 index 0000000000..bfb0f202af --- /dev/null +++ b/tests/experimental/endpoint/windows_ad_domain_replication_acl_addition.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Domain Replication ACL Addition Unit Test +tests: +- name: Windows AD Domain Replication ACL Addition + file: endpoint/windows_ad_domain_replication_acl_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/aclmodification/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.test.yml b/tests/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.test.yml new file mode 100644 index 0000000000..c03cc61e4b --- /dev/null +++ b/tests/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.test.yml @@ -0,0 +1,15 @@ +name: Windows AD Privileged Account SID History Addition Unit Test +tests: +- name: Windows AD Privileged Account SID History Addition + file: experimental/windows_ad_privileged_account_sid_history_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true + + diff --git a/tests/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml b/tests/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml new file mode 100644 index 0000000000..36f995790f --- /dev/null +++ b/tests/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml @@ -0,0 +1,13 @@ +name: Windows AD Rogue Domain Controller Network Activity Unit Test +tests: +- name: Windows AD Rogue Domain Controller Network Activity + file: network/windows_ad_rogue_domain_controller_network_activity.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: zeek-dce_rpc.log + data: https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1207/mimikatz/zeek-dce_rpc.log + source: /opt/zeek/logs/current/dce_rpc.log + sourcetype: bro:dce_rpc:json + update_timestamp: true