Files
splunk-security_content/escu/searches/detection_wmi_process_launch.json
2018-12-20 14:32:13 -05:00

89 lines
2.8 KiB
JSON

{
"asset_type": "Endpoint",
"channel": "ESCU",
"confidence": "medium",
"correlation_rule": {
"notable": {
"nes_fields": "dest, user, process",
"rule_description": "This search looks for child processes of WmiPrvSE.exe, which indicates that a process was launched via WMI.",
"rule_title": "Process launched via WMI on $dest$"
},
"risk": {
"risk_object": "dest",
"risk_object_type": [
"system"
],
"risk_score": 70
},
"suppress": {
"suppress_fields": "dest,user",
"suppress_period": "28800s"
}
},
"creation_date": "2018-10-23",
"data_metadata": {
"data_source": [
"Endpoint Intel"
],
"data_sourcetypes": [
"XmlWinEventLog:Microsoft-Windows-Sysmon/Operational"
],
"providing_technologies": [
"Carbon Black Response",
"Sysmon",
"Tanium",
"Ziften"
]
},
"eli5": "Attackers are increasingly abusing Windows Management Infrastructure (WMI) for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for processes launched via WMI, either remotely or locally, by looking for processes launched by WmiPrvSE.exe, which is the process WMI uses to execute new processes and commands.",
"how_to_implement": "To successfully implement this search, you must be ingesting logs with both the process name and command-line from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.",
"known_false_positives": "Although unlikely, administrators may use wmi to execute commands for legitimate purposes.",
"maintainers": [
{
"company": "Splunk",
"email": "rvaldez@splunk.com",
"name": "Rico Valdez"
}
],
"mappings": {
"cis20": [
"CIS 3",
"CIS 5"
],
"kill_chain_phases": [
"Actions on Objectives"
],
"mitre_attack": [
"Execution",
"Windows Management Instrumentation"
],
"nist": [
"PR.PT",
"PR.AT",
"PR.AC",
"PR.IP"
]
},
"modification_date": "2018-10-23",
"original_authors": [
{
"company": "Splunk",
"email": "rvaldez@splunk.com",
"name": "Rico Valdez"
}
],
"scheduling": {
"cron_schedule": "0 * * * *",
"earliest_time": "-70m@m",
"latest_time": "-10m@m"
},
"search": "(sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational OR tag=process) parent_process=*WmiPrvSE.exe | stats count min(_time) as firstTime max(_time) as lastTime by dest, user, parent_process, process, cmdline | `ctime(firstTime)`| `ctime(lastTime)`",
"search_description": "This search looks for processes launched via WMI.",
"search_id": "24869767-8579-485d-9a4f-d9ddfd8f0cac",
"search_name": "Process Execution via WMI",
"search_type": "detection",
"security_domain": "endpoint",
"spec_version": 1,
"version": "1.0"
}