Files
splunk-security_content/detections/endpoint/potentially_malicious_code_on_commandline.yml
2022-03-09 14:43:09 +01:00

81 lines
3.5 KiB
YAML

name: Potentially malicious code on commandline
id: 9c53c446-757e-11ec-871d-acde48001122
version: 1
date: '2022-01-14'
author: Michael Hart, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic uses a pretrained machine learning text classifier
to detect potentially malicious commandlines. The model identifies unusual combinations
of keywords found in samples of commandlines where adversaries executed powershell
code, primarily for C2 communication. For example, adversaries will leverage IO
capabilities such as "streamreader" and "webclient", threading capabilties such
as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic
operations like "computehash". Although observing one of these keywords in a commandline
script is possible, combinations of keywords observed in attack data are not typically
found in normal usage of the commandline. The model will output a score where all
values above zero are suspicious, anything greater than one particularly so.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name
Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` |
where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score`
| apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'',
process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits)
orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `potentially_malicious_code_on_commandline_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. You will also need to install the Machine Learning Toolkit version 5.3
or above to apply the pretrained model.
known_false_positives: This model is an anomaly detector that identifies usage of
APIs and scripting constructs that are correllated with malicious activity. These
APIs and scripting constructs are part of the programming langauge and advanced
scripts may generate false positives.
references:
- https://attack.mitre.org/techniques/T1059/003/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
tags:
analytic_story:
- Suspicious Command-Line Executions
confidence: 20
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log
impact: 60
kill_chain_phases:
- Exploitation
message: Unusual command-line execution with hallmarks of malicious activity run
by $user$ found on $dest$ with commandline $process$
mitre_attack_id:
- T1059.003
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.parent_process_name
- Processes.process_name
- Processes.parent_process
- Processes.user
- Processes.dest
risk_score: 12
security_domain: endpoint
supported_tas:
- Splunk_TA_microsoft_sysmon
asset_type: Endpoint