mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
166 lines
5.0 KiB
Markdown
166 lines
5.0 KiB
Markdown
---
|
|
title: "Linux Disable Services"
|
|
excerpt: "Service Stop
|
|
"
|
|
categories:
|
|
- Endpoint
|
|
last_modified_at: 2022-04-22
|
|
toc: true
|
|
toc_label: ""
|
|
tags:
|
|
- Service Stop
|
|
- Impact
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
- Endpoint
|
|
---
|
|
|
|
|
|
|
|
[Try in Splunk Security Cloud](https://www.splunk.com/en_us/products/cyber-security.html){: .btn .btn--success}
|
|
|
|
#### Description
|
|
|
|
The following analytic is to detect events that attempts to disable a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then delete it. Adversaries utilize this technique like industroyer2 malware to terminate security services or other related services to continue there objective as a destructive payload.
|
|
|
|
- **Type**: [TTP](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types)
|
|
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
|
- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)
|
|
- **Last Updated**: 2022-04-22
|
|
- **Author**: Teoderick Contreras, Splunk
|
|
- **ID**: f2e08a38-6689-4df4-ad8c-b51c16262316
|
|
|
|
|
|
#### Annotations
|
|
|
|
<details>
|
|
<summary>ATT&CK</summary>
|
|
|
|
<div markdown="1">
|
|
|
|
|
|
| ID | Technique | Tactic |
|
|
| -------------- | ---------------- |-------------------- |
|
|
| [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact |
|
|
|
|
</div>
|
|
</details>
|
|
|
|
|
|
<details>
|
|
<summary>Kill Chain Phase</summary>
|
|
|
|
<div markdown="1">
|
|
|
|
* Exploitation
|
|
|
|
|
|
</div>
|
|
</details>
|
|
|
|
|
|
<details>
|
|
<summary>NIST</summary>
|
|
|
|
<div markdown="1">
|
|
|
|
* DE.CM
|
|
|
|
|
|
|
|
</div>
|
|
</details>
|
|
|
|
<details>
|
|
<summary>CIS20</summary>
|
|
|
|
<div markdown="1">
|
|
|
|
* CIS 3
|
|
* CIS 5
|
|
* CIS 16
|
|
|
|
|
|
|
|
</div>
|
|
</details>
|
|
|
|
<details>
|
|
<summary>CVE</summary>
|
|
|
|
<div markdown="1">
|
|
|
|
|
|
</div>
|
|
</details>
|
|
|
|
#### Search
|
|
|
|
```
|
|
|
|
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name IN ("systemctl", "service", "svcadm") Processes.process = "* disable*" by Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.process_guid Processes.dest Processes.user
|
|
| `drop_dm_object_name(Processes)`
|
|
| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`
|
|
| `linux_disable_services_filter`
|
|
```
|
|
|
|
#### Macros
|
|
The SPL above uses the following Macros:
|
|
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
|
|
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
|
|
|
|
> :information_source:
|
|
> **linux_disable_services_filter** is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
|
|
|
|
#### Required field
|
|
* _time
|
|
* Processes.dest
|
|
* Processes.user
|
|
* Processes.parent_process_name
|
|
* Processes.process_name
|
|
* Processes.process
|
|
* Processes.process_id
|
|
* Processes.parent_process_id
|
|
|
|
|
|
#### How To Implement
|
|
To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you can use the Add-on for Linux Sysmon from Splunkbase.
|
|
|
|
#### Known False Positives
|
|
Administrator or network operator can use this application for automation purposes. Please update the filter macros to remove false positives.
|
|
|
|
#### Associated Analytic story
|
|
* [Industroyer2](/stories/industroyer2)
|
|
|
|
|
|
|
|
|
|
#### RBA
|
|
|
|
| Risk Score | Impact | Confidence | Message |
|
|
| ----------- | ----------- |--------------|--------------|
|
|
| 49.0 | 70 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified attempting to disable services on endpoint $dest$ by $user$. |
|
|
|
|
|
|
> :information_source:
|
|
> The Risk Score is calculated by the following formula: Risk Score = (Impact * Confidence/100). Initial Confidence and Impact is set by the analytic author.
|
|
|
|
#### Reference
|
|
|
|
* [https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/](https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/)
|
|
* [https://cert.gov.ua/article/39518](https://cert.gov.ua/article/39518)
|
|
|
|
|
|
|
|
#### Test Dataset
|
|
Replay any dataset to Splunk Enterprise by using our [replay.py](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui).
|
|
Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server)
|
|
|
|
|
|
* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_service_stop_disable/sysmon_linux.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_service_stop_disable/sysmon_linux.log)
|
|
|
|
|
|
|
|
[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/linux_disable_services.yml) \| *version*: **1** |