Files
splunk-security_content/detections/endpoint/suspicious_process_file_path.yml
2024-06-26 14:41:53 +00:00

117 lines
4.7 KiB
YAML

name: Suspicious Process File Path
id: 9be25988-ad82-11eb-a14f-acde48001122
version: 2
date: '2024-05-12'
author: Teoderick Contreras, Splunk
status: production
type: TTP
description: The following analytic identifies processes running from file paths not
typically associated with legitimate software. It leverages data from Endpoint Detection
and Response (EDR) agents, focusing on specific process paths within the Endpoint
data model. This activity is significant because adversaries often use unconventional
file paths to execute malicious code without requiring administrative privileges.
If confirmed malicious, this behavior could indicate an attempt to bypass security
controls, leading to unauthorized software execution, potential system compromise,
and further malicious activities within the environment.
data_source:
- Sysmon EventID 1
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\windows\\fonts\\*"
OR Processes.process_path = "*\\windows\\temp\\*" OR Processes.process_path = "*\\users\\public\\*"
OR Processes.process_path = "*\\windows\\debug\\*" OR Processes.process_path = "*\\Users\\Administrator\\Music\\*"
OR Processes.process_path = "*\\Windows\\servicing\\*" OR Processes.process_path
= "*\\Users\\Default\\*" OR Processes.process_path = "*Recycle.bin*" OR Processes.process_path
= "*\\Windows\\Media\\*" OR Processes.process_path = "\\Windows\\repair\\*" OR Processes.process_path
= "*\\temp\\*" OR Processes.process_path = "*\\PerfLogs\\*" by Processes.parent_process_name
Processes.parent_process Processes.process_path Processes.dest Processes.user |
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `suspicious_process_file_path_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
you must ingest logs that contain the process GUID, process name, and parent process.
Additionally, you must ingest complete command-line executions. These logs must
be processed using the appropriate Splunk Technology Add-ons that are specific to
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: Administrators may allow execution of specific binaries in
non-standard paths. Filter as needed.
references:
- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://twitter.com/pr0xylife/status/1590394227758104576
- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
tags:
analytic_story:
- Double Zero Destructor
- Graceful Wipe Out Attack
- AsyncRAT
- WhisperGate
- Prestige Ransomware
- DarkGate Malware
- AgentTesla
- Brute Ratel C4
- RedLine Stealer
- Rhysida Ransomware
- Swift Slicer
- IcedID
- DarkCrystal RAT
- Chaos Ransomware
- PlugX
- Industroyer2
- Azorult
- Remcos
- XMRig
- Qakbot
- Volt Typhoon
- Hermetic Wiper
- Warzone RAT
- Trickbot
- Amadey
- BlackByte Ransomware
- LockBit Ransomware
- CISA AA23-347A
- Data Destruction
- Phemedrone Stealer
asset_type: Endpoint
confidence: 50
impact: 70
message: Suspicious process $process_name$ running from a suspicious process path-
$process_path$ on host- $dest$
mitre_attack_id:
- T1543
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: process_path
type: Process Name
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_path
- Processes.dest
- Processes.user
risk_score: 35
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog