name: Windows Apache Benchmark Binary id: 894f48ea-8d85-4dcd-9132-c66cdb407c9b version: 1 date: '2022-11-21' author: Michael Haag, Splunk type: Anomaly datamodel: - Endpoint description: The following analytic identifies a default behavior of a MetaSploit payload. MetaSploit uses Apache Benchmark to generate payloads. The payloads contain standard artifacts including "Apache Benchmark" and the original file name is always ab.exe. During triage, review the process and it's path. It is possible network connections spawned from it. Review parallel processes for further behaviors. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.original_file_name=ab.exe by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_apache_benchmark_binary_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. known_false_positives: False positives should be limited as there is a small subset of binaries that contain the original file name of ab.exe. Filter as needed. references: - https://seclists.org/metasploit/2013/q3/13 tags: analytic_story: - MetaSploit asset_type: Endpoint cis20: - CIS 3 - CIS 5 - CIS 16 confidence: 100 context: - Source:Endpoint - Stage:Defense Evasion dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/metasploit/apachebench_windows-sysmon.log impact: 100 kill_chain_phases: - Exploitation message: A known MetaSploit default payload has been identified on $dest$ ran by $user$, $parent_process_name$ spawning $process_name$. mitre_attack_id: - T1059 nist: - DE.CM observable: - name: user type: User role: - Victim - name: dest type: Hostname role: - Victim - name: parent_process_name type: Process role: - Parent Process - name: process_name type: Process role: - Child Process product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - Processes.dest - Processes.user - Processes.parent_process_name #parent process name - Processes.parent_process #parent cmdline - Processes.original_file_name - Processes.process_name #process name - Processes.process #process cmdline - Processes.process_id - Processes.parent_process_path - Processes.process_path - Processes.parent_process_id risk_score: 100 security_domain: endpoint