Files
splunk-security_content/detections/endpoint/recon_using_wmi_class.yml
2023-01-18 14:55:46 +01:00

76 lines
3.4 KiB
YAML

name: Recon Using WMI Class
id: 018c1972-ca07-11eb-9473-acde48001122
version: 2
date: '2022-10-10'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel: []
description: The following analytic identifies suspicious PowerShell via EventCode
4104, where WMI is performing an event query looking for running processes or running
services. This technique is commonly found where the adversary will identify services
and system information on the compromised machine. During triage, review parallel
processes within the same timeframe. Review the full script block to identify other
related artifacts.
search: '`powershell` EventCode=4104 (ScriptBlockText= "*SELECT*" OR ScriptBlockText= "*Get-WmiObject*")
AND (ScriptBlockText= "*Win32_Bios*" OR ScriptBlockText= "*Win32_OperatingSystem*" OR ScriptBlockText= "*Win32_Processor*"
OR ScriptBlockText= "*Win32_ComputerSystem*" OR ScriptBlockText= "*Win32_PnPEntity*"
OR ScriptBlockText= "*Win32_ShadowCopy*" OR ScriptBlockText= "*Win32_DiskDrive*" OR ScriptBlockText= "*Win32_PhysicalMemory*") | stats count min(_time) as firstTime max(_time)
as lastTime by EventCode ScriptBlockText Computer UserID | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `recon_using_wmi_class_filter`'
how_to_implement: To successfully implement this analytic, you will need to enable
PowerShell Script Block Logging on some or all endpoints. Additional setup here
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
known_false_positives: network administrator may used this command for checking purposes
references:
- https://news.sophos.com/en-us/2020/05/12/maze-ransomware-1-year-counting/
- https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
- https://blog.palantir.com/tampering-with-windows-event-tracing-background-offense-and-defense-4be7ac62ac63
- https://static1.squarespace.com/static/552092d5e4b0661088167e5c/t/59c1814829f18782e24f1fe2/1505853768977/Windows+PowerShell+Logging+Cheat+Sheet+ver+Sept+2017+v2.1.pdf
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
- https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
- https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- Industroyer2
- Qakbot
- LockBit Ransomware
confidence: 80
context:
- Source:Endpoint
- Stage:Discovery
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/reconusingwmi.log
impact: 75
kill_chain_phases:
- Reconnaissance
message: A suspicious powershell script contains host recon command in $ScriptBlockText$
with EventCode $EventCode$ in host $Computer$
mitre_attack_id:
- T1592
- T1059.001
observable:
- name: Computer
type: Hostname
role:
- Victim
- name: User
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- ScriptBlockText
- Computer
- UserID
risk_score: 60
security_domain: endpoint
asset_type: Endpoint