mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
74 lines
3.0 KiB
YAML
74 lines
3.0 KiB
YAML
name: Spoolsv Suspicious Process Access
|
|
id: 799b606e-da81-11eb-93f8-acde48001122
|
|
version: 1
|
|
date: '2021-07-01'
|
|
author: Mauricio Velazco, Michael Haag, Teoderick Contreras, Splunk
|
|
type: TTP
|
|
datamodel:
|
|
- Endpoint
|
|
description: This analytic identifies a suspicious behavior related to PrintNightmare,
|
|
or CVE-2021-34527 previously (CVE-2021-1675), to gain privilege escalation on the
|
|
vulnerable machine. This exploit attacks a critical Windows Print Spooler Vulnerability
|
|
to elevate privilege. This detection is to look for suspicious process access made
|
|
by the spoolsv.exe that may related to the attack.
|
|
search: '`sysmon` EventCode=10 SourceImage = "*\\spoolsv.exe" CallTrace = "*\\Windows\\system32\\spool\\DRIVERS\\x64\\*"
|
|
TargetImage IN ("*\\rundll32.exe", "*\\spoolsv.exe") GrantedAccess = 0x1fffff |
|
|
stats count min(_time) as firstTime max(_time) as lastTime by Computer SourceImage
|
|
TargetImage GrantedAccess CallTrace EventCode ProcessID| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)` | `spoolsv_suspicious_process_access_filter`'
|
|
how_to_implement: To successfully implement this search, you need to be ingesting
|
|
logs with process access event where SourceImage, TargetImage, GrantedAccess and
|
|
CallTrace executions from your endpoints. If you are using Sysmon, you must have
|
|
at least version 6.0.4 of the Sysmon TA. Tune and filter known instances of spoolsv.exe.
|
|
known_false_positives: Unknown. Filter as needed.
|
|
references:
|
|
- https://github.com/cube0x0/impacket/commit/73b9466c17761384ece11e1028ec6689abad6818
|
|
- https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/
|
|
- https://blog.truesec.com/2021/06/30/exploitable-critical-rce-vulnerability-allows-regular-users-to-fully-compromise-active-directory-printnightmare-cve-2021-1675/
|
|
- https://www.reddit.com/r/msp/comments/ob6y02/critical_vulnerability_printnightmare_exposes
|
|
tags:
|
|
analytic_story:
|
|
- PrintNightmare CVE-2021-34527
|
|
automated_detection_testing: passed
|
|
confidence: 90
|
|
context:
|
|
- Source:Endpoint
|
|
- Stage:Privilege Escalation
|
|
- Stage:Defense Evasion
|
|
- Scope:Local
|
|
dataset:
|
|
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/printnightmare/windows-sysmon.log
|
|
impact: 80
|
|
kill_chain_phases:
|
|
- Exploitation
|
|
message: $SourceImage$ was GrantedAccess open access to $TargetImage$ on endpoint
|
|
$Computer$. This behavior is suspicious and related to PrintNightmare.
|
|
mitre_attack_id:
|
|
- T1068
|
|
observable:
|
|
- name: Computer
|
|
type: Endpoint
|
|
role:
|
|
- Victim
|
|
- name: ProcessID
|
|
type: Process
|
|
role:
|
|
- Parent Process
|
|
- name: TargetImage
|
|
type: Process Name
|
|
role:
|
|
- Target
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- SourceImage
|
|
- TargetImage
|
|
- GrantedAccess
|
|
- CallTrace
|
|
- EventCode
|
|
risk_score: 72
|
|
security_domain: endpoint
|