mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
78 lines
3.3 KiB
YAML
78 lines
3.3 KiB
YAML
name: Detect Exchange Web Shell
|
|
id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a
|
|
version: 2
|
|
date: '2021-03-09'
|
|
author: Michael Haag, Shannon Davis, Splunk
|
|
type: TTP
|
|
datamodel:
|
|
- Endpoint
|
|
description: 'The following query identifies suspicious .aspx created in 3 paths identified
|
|
by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM
|
|
group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`,
|
|
and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious
|
|
on the surface. inspect the contents for script code inside. Identify additional
|
|
log sources, IIS included, to review source and other potential exploitation.'
|
|
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
|
where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name
|
|
Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [|
|
|
tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
|
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*",
|
|
"*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx"
|
|
by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name
|
|
Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time
|
|
file_name file_path process_name process_path process] | dedup file_create_time
|
|
| table dest file_create_time, file_name, file_path, process_name | `detect_exchange_web_shell_filter`'
|
|
how_to_implement: To successfully implement this search you need to be ingesting information
|
|
on process that include the name of the process responsible for the changes from
|
|
your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
|
|
node.
|
|
known_false_positives: The query is structured in a way that `action` (read, create)
|
|
is not defined. Review the results of this query, filter, and tune as necessary.
|
|
It may be necessary to generate this query specific to your endpoint product.
|
|
references:
|
|
- https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv
|
|
tags:
|
|
analytic_story:
|
|
- HAFNIUM Group
|
|
automated_detection_testing: passed
|
|
confidence: 90
|
|
context:
|
|
- Source:Endpoint
|
|
- Stage:Exploitation
|
|
dataset:
|
|
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log
|
|
impact: 90
|
|
kill_chain_phases:
|
|
- Exploitation
|
|
message: A file - $file_name$ was written to disk that is related to IIS exploitation
|
|
previously performed by HAFNIUM. Review further file modifications on endpoint
|
|
$dest$ by user $user$.
|
|
mitre_attack_id:
|
|
- T1505.003
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
- name: file_name
|
|
type: File Name
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Filesystem.file_path
|
|
- Filesystem.process_id
|
|
- Filesystem.file_name
|
|
- Filesystem.file_hash
|
|
- Filesystem.user
|
|
risk_score: 81
|
|
security_domain: endpoint
|