Files
2021-07-20 17:49:09 +00:00

68 lines
2.4 KiB
YAML

name: ICACLS Grant Command
id: b1b1e316-accc-11eb-a9b4-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies potential adversaries that modify the security
permission of a specific file or directory. This technique is commonly seen in APT
tradecraft and coinminer scripts to evade detections and restrict access to their
component files.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe"
OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe"
AND Processes.process = "*/grant*" by Processes.parent_process_name Processes.process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `icacls_grant_command_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used.
known_false_positives: Unknown. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
- Ransomware
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
message: Process name $process_name$ with grant argument executed by $user$ to change
security permission of a specific file or directory on host $dest$
mitre_attack_id:
- T1222
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process_id
- Processes.process
risk_score: 49
security_domain: endpoint