name: Process Kill Base On File Path id: 5ffaa42c-acdb-11eb-9ad3-acde48001122 version: 2 date: '2021-05-04' author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint description: The following analytic identifies the use of `wmic.exe` using `delete` to remove a executable path. This is typically ran via a batch file during beginning stages of an adversary setting up for mining on an endpoint. search: '| tstats `security_content_summariesonly` values(Processes.process) as process values(Processes.process_id) as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_wmic` AND Processes.process="*process*" AND Processes.process="*executablepath*" AND Processes.process="*delete*" by Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `process_kill_base_on_file_path_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. known_false_positives: Unknown. references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: analytic_story: - XMRig confidence: 80 context: - Source:Endpoint - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log impact: 70 kill_chain_phases: - Exploitation message: A process $process_name$ attempt to kill process by its file path using commandline $process$ in host $dest$ mitre_attack_id: - T1562.001 - T1562 observable: - name: dest type: Hostname role: - Victim - name: user type: User role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - Processes.dest - Processes.user - Processes.parent_process_name - Processes.parent_process - Processes.original_file_name - Processes.process_name - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id risk_score: 56 security_domain: endpoint supported_tas: - Splunk_TA_microsoft_sysmon asset_type: Endpoint