Files
splunk-security_content/detections/endpoint/excessive_usage_of_taskkill.yml
2022-06-09 16:07:40 +02:00

74 lines
2.5 KiB
YAML

name: Excessive Usage Of Taskkill
id: fe5bca48-accb-11eb-a67c-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: This analytic identifies excessive usage of `taskkill.exe` application.
This application is commonly used by adversaries to evade detections by killing
security product processes or even other processes to evade detection.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "taskkill.exe" by
Processes.parent_process_name Processes.process_name Processes.dest Processes.user
_time span=1m | where count >=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_usage_of_taskkill_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used.
known_false_positives: Unknown. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
- Azorult
confidence: 70
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
impact: 40
kill_chain_phases:
- Exploitation
message: Excessive usage of taskkill.exe with process id $process_id$ (more than
10 within 1m) has been detected on $dest$ with a parent process of $parent_process_name$.
mitre_attack_id:
- T1562.001
- T1562
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: dest
type: Endpoint
role:
- Victim
- name: parent_process_name
type: Process Name
role:
- Parent Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process
- Processes.process_id
risk_score: 28
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint