Files
splunk-security_content/dev/endpoint/detect_sharphound_file_modifications.yml
2023-01-20 13:24:15 +01:00

85 lines
3.1 KiB
YAML

name: Detect SharpHound File Modifications
id: 42b4b438-beed-11eb-ba1d-acde48001122
version: 2
date: '2022-10-09'
author: Michael Haag, Splunk
status: production
type: TTP
description: SharpHound is used as a reconnaissance collector, ingestor, for BloodHound.
SharpHound will query the domain controller and begin gathering all the data related
to the domain and trusts. For output, it will drop a .zip file upon completion following
a typical pattern that is often not changed. This analytic focuses on the default
file name scheme. Note that this may be evaded with different parameters within
SharpHound, but that depends on the operator. `-randomizefilenames` and `-encryptzip`
are two examples. In addition, executing SharpHound via .exe or .ps1 without any
command-line arguments will still perform activity and dump output to the default
filename. Example default filename `20210601181553_BloodHound.zip`. SharpHound creates
multiple temp files following the same pattern `20210601182121_computers.json`,
`domains.json`, `gpos.json`, `ous.json` and `users.json`. Tuning may be required,
or remove these json's entirely if it is too noisy. During traige, review parallel
processes for further suspicious behavior. Typically, the process executing the
`.ps1` ingestor will be PowerShell.
data_source:
- Sysmon Event ID 11
search:
selection1:
Filesystem.file_name:
- '*bloodhound.zip'
- '*_computers.json'
- '*_gpos.json'
- '*_domains.json'
- '*_users.json'
- '*_groups.json'
- '*_ous.json'
- '*_containers.json'
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on file modifications that include the name of the process, and file, responsible
for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem`
node.
known_false_positives: False positives should be limited as the analytic is specific
to a filename with extension .zip. Filter as needed.
references:
- https://attack.mitre.org/software/S0521/
- https://thedfirreport.com/?s=bloodhound
- https://github.com/BloodHoundAD/BloodHound/tree/master/Collectors
- https://github.com/BloodHoundAD/SharpHound3
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md#atomic-test-2---run-bloodhound-from-local-disk
tags:
analytic_story:
- Discovery Techniques
- Ransomware
asset_type: Endpoint
confidence: 80
impact: 30
message: Potential SharpHound file modifications identified on $dest$
mitre_attack_id:
- T1087.002
- T1069.001
- T1482
- T1087.001
- T1087
- T1069.002
- T1069
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: User
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 24
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/sharphound/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog