mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
89 lines
3.6 KiB
YAML
89 lines
3.6 KiB
YAML
name: Windows Replication Through Removable Media
|
|
id: 60df805d-4605-41c8-bbba-57baa6a4eb97
|
|
version: 1
|
|
date: '2023-01-17'
|
|
author: Teoderick Contreras, Splunk
|
|
type: TTP
|
|
datamodel:
|
|
- Endpoint
|
|
description: This analytic is developed to detect suspicious executable or script files created or dropped
|
|
in the root drive of a targeted host. This technique is commonly used by threat actors, adversaries or
|
|
even red teamers to replicate or spread in possible removable drives. Back then, WORM malware was popular
|
|
for this technique where it would drop a copy of itself in the root drive to be able to spread or to have
|
|
a lateral movement in other network machines. Nowadays, Ransomware like CHAOS ransomware also use this
|
|
technique to spread its malicious code in possible removable drives. Thi TTP detection can be a good
|
|
indicator that a process might create a persistence technique or lateral movement of a targeted machine.
|
|
We suggest checking the process name that creates this event, the file created, user type, and the reason
|
|
why that executable or scripts are dropped in the root drive.
|
|
search: '|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem
|
|
where (Filesystem.file_name = *.exe OR Filesystem.file_name = *.dll OR Filesystem.file_name = *.sys
|
|
OR Filesystem.file_name = *.com OR Filesystem.file_name = *.vbs OR Filesystem.file_name = *.vbe
|
|
OR Filesystem.file_name = *.js OR Filesystem.file_name= *.bat OR Filesystem.file_name = *.cmd
|
|
OR Filesystem.file_name = *.pif)
|
|
by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.user
|
|
| `drop_dm_object_name(Filesystem)`
|
|
| eval dropped_file_path = split(file_path, "\\")
|
|
| eval dropped_file_path_split_count = mvcount(dropped_file_path)
|
|
| eval root_drive = mvindex(dropped_file_path,0)
|
|
| where LIKE(root_drive, "%:") AND dropped_file_path_split_count = 2 AND root_drive!= "C:"
|
|
| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`
|
|
| `windows_replication_through_removable_media_filter`'
|
|
how_to_implement: To successfully implement this search you need to be ingesting information
|
|
on process that include the name of the Filesystem responsible for the changes from
|
|
your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
|
|
known_false_positives: Administrators may allow creation of script or exe in the paths
|
|
specified. Filter as needed.
|
|
references:
|
|
- https://attack.mitre.org/techniques/T1204/002/
|
|
- https://www.fortinet.com/blog/threat-research/chaos-ransomware-variant-sides-with-russia
|
|
tags:
|
|
analytic_story:
|
|
- Chaos Ransomware
|
|
asset_type: Endpoint
|
|
cis20:
|
|
- CIS 3
|
|
- CIS 5
|
|
- CIS 16
|
|
confidence: 80
|
|
context:
|
|
- Source:Endpoint
|
|
- Stage:Lateral Movement
|
|
dataset:
|
|
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/chaos_ransomware/spread_in_root_drives/sysmon.log
|
|
impact: 80
|
|
kill_chain_phases:
|
|
- Exploitation
|
|
message: executable or script $file_path$ was drop in root drive $root_drive$ in $dest$
|
|
mitre_attack_id:
|
|
- T1091
|
|
nist:
|
|
- DE.CM
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: process_id
|
|
type: Process
|
|
role:
|
|
- Attacker
|
|
- name: file_name
|
|
type: File Name
|
|
role:
|
|
- Other
|
|
- Attacker
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Filesystem.file_path
|
|
- Filesystem.file_create_time
|
|
- Filesystem.process_id
|
|
- Filesystem.file_name
|
|
- Filesystem.user
|
|
risk_score: 64
|
|
security_domain: endpoint
|