name: Detect SharpHound File Modifications id: 42b4b438-beed-11eb-ba1d-acde48001122 version: 2 date: '2022-10-09' author: Michael Haag, Splunk status: production type: TTP description: SharpHound is used as a reconnaissance collector, ingestor, for BloodHound. SharpHound will query the domain controller and begin gathering all the data related to the domain and trusts. For output, it will drop a .zip file upon completion following a typical pattern that is often not changed. This analytic focuses on the default file name scheme. Note that this may be evaded with different parameters within SharpHound, but that depends on the operator. `-randomizefilenames` and `-encryptzip` are two examples. In addition, executing SharpHound via .exe or .ps1 without any command-line arguments will still perform activity and dump output to the default filename. Example default filename `20210601181553_BloodHound.zip`. SharpHound creates multiple temp files following the same pattern `20210601182121_computers.json`, `domains.json`, `gpos.json`, `ous.json` and `users.json`. Tuning may be required, or remove these json's entirely if it is too noisy. During traige, review parallel processes for further suspicious behavior. Typically, the process executing the `.ps1` ingestor will be PowerShell. data_source: - Sysmon Event ID 11 search: selection1: Filesystem.file_name: - '*bloodhound.zip' - '*_computers.json' - '*_gpos.json' - '*_domains.json' - '*_users.json' - '*_groups.json' - '*_ous.json' - '*_containers.json' condition: selection1 how_to_implement: To successfully implement this search you need to be ingesting information on file modifications that include the name of the process, and file, responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. known_false_positives: False positives should be limited as the analytic is specific to a filename with extension .zip. Filter as needed. references: - https://attack.mitre.org/software/S0521/ - https://thedfirreport.com/?s=bloodhound - https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors - https://github.com/BloodHoundAD/SharpHound3 - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk tags: analytic_story: - Discovery Techniques - Ransomware asset_type: Endpoint confidence: 80 impact: 30 message: Potential SharpHound file modifications identified on $dest$ mitre_attack_id: - T1087.002 - T1069.001 - T1482 - T1087.001 - T1087 - T1069.002 - T1069 observable: - name: dest type: Endpoint role: - Victim - name: User type: User role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 24 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog