mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
56 lines
1.7 KiB
YAML
56 lines
1.7 KiB
YAML
name: Supernova Webshell
|
|
id: 2ec08a09-9ff1-4dac-b59f-1efd57972ec1
|
|
version: 1
|
|
date: '2021-01-06'
|
|
author: John Stoner, Splunk
|
|
status: experimental
|
|
type: TTP
|
|
description: This search aims to detect the Supernova webshell used in the SUNBURST
|
|
attack.
|
|
data_source: []
|
|
search: '| tstats `security_content_summariesonly` count from datamodel=Web.Web where
|
|
web.url=*logoimagehandler.ashx*codes* OR Web.url=*logoimagehandler.ashx*clazz* OR
|
|
Web.url=*logoimagehandler.ashx*method* OR Web.url=*logoimagehandler.ashx*args* by
|
|
Web.src Web.dest Web.url Web.vendor_product Web.user Web.http_user_agent _time span=1s
|
|
| `supernova_webshell_filter`'
|
|
how_to_implement: To successfully implement this search, you need to be monitoring
|
|
web traffic to your Solarwinds Orion. The logs should be ingested into splunk and
|
|
populating/mapped to the Web data model.
|
|
known_false_positives: There might be false positives associted with this detection
|
|
since items like args as a web argument is pretty generic.
|
|
references:
|
|
- https://www.splunk.com/en_us/blog/security/detecting-supernova-malware-solarwinds-continued.html
|
|
- https://www.guidepointsecurity.com/blog/supernova-solarwinds-net-webshell-analysis/
|
|
tags:
|
|
analytic_story:
|
|
- NOBELIUM Group
|
|
asset_type: Web Server
|
|
confidence: 50
|
|
impact: 50
|
|
message: tbd
|
|
mitre_attack_id:
|
|
- T1505.003
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Web.url
|
|
- Web.src
|
|
- Web.dest
|
|
- Web.vendor_product
|
|
- Web.user
|
|
- Web.http_user_agent
|
|
risk_score: 25
|
|
security_domain: network
|