mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
71 lines
2.4 KiB
YAML
71 lines
2.4 KiB
YAML
name: Common Ransomware Notes
|
|
id: ada0f478-84a8-4641-a3f1-d82362d6bd71
|
|
version: 4
|
|
date: '2020-11-09'
|
|
author: David Dorsey, Splunk
|
|
status: production
|
|
type: Hunting
|
|
description: The search looks for files created with names matching those typically
|
|
used in ransomware notes that tell the victim how to get their data back.
|
|
data_source:
|
|
- Sysmon Event ID 11
|
|
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
|
as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path)
|
|
as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name | `drop_dm_object_name(Filesystem)`
|
|
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ransomware_notes`
|
|
| `common_ransomware_notes_filter`'
|
|
how_to_implement: You must be ingesting data that records file-system activity from
|
|
your hosts to populate the Endpoint Filesystem data-model node. This is typically
|
|
populated via endpoint detection-and-response product, such as Carbon Black, or
|
|
via other endpoint data sources, such as Sysmon. The data used for this search is
|
|
typically generated via logs that report file-system reads and writes.
|
|
known_false_positives: It's possible that a legitimate file could be created with
|
|
the same name used by ransomware note files.
|
|
references: []
|
|
tags:
|
|
analytic_story:
|
|
- SamSam Ransomware
|
|
- Ransomware
|
|
- Ryuk Ransomware
|
|
- Clop Ransomware
|
|
- Chaos Ransomware
|
|
- LockBit Ransomware
|
|
asset_type: Endpoint
|
|
confidence: 100
|
|
impact: 90
|
|
message: A file - $file_name$ was written to disk on endpoint $dest$ by user $user$,
|
|
this is indicative of a known ransomware note file and should be reviewed immediately.
|
|
mitre_attack_id:
|
|
- T1485
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
- name: file_name
|
|
type: File Name
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Filesystem.user
|
|
- Filesystem.dest
|
|
- Filesystem.file_path
|
|
- Filesystem.file_name
|
|
risk_score: 90
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: xmlwineventlog
|