Files
splunk-security_content/detections/endpoint/icacls_deny_command.yml
2022-06-09 16:07:40 +02:00

71 lines
2.5 KiB
YAML

name: Icacls Deny Command
id: cf8d753e-a8fe-11eb-8f58-acde48001122
version: 1
date: '2021-04-29'
author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: This analytic identifies a potential adversary that changes the security
permission of a specific file or directory. This technique is commonly seen in APT
tradecraft or coinminer scripts. This behavior is meant to evade detection and prevent
access to their component files.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe"
OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe"
AND Processes.process = "*/deny*" by Processes.parent_process_name Processes.process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `icacls_deny_command_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used.
known_false_positives: Unknown. It is possible some administrative scripts use ICacls.
Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
- Azorult
confidence: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
impact: 90
kill_chain_phases:
- Exploitation
message: Process name $process_name$ with deny argument executed by $user$ to change
security permission of a specific file or directory on host $dest$
mitre_attack_id:
- T1222
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process_id
- Processes.process
risk_score: 72
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint