Files
splunk-security_content/dev/endpoint/ryuk_wake_on_lan_command.yml
2023-01-23 09:38:17 +01:00

65 lines
2.3 KiB
YAML

name: Ryuk Wake on LAN Command
id: 538d0152-7aaa-11eb-beaa-acde48001122
version: 1
date: '2021-03-01'
author: Michael Haag, Splunk
status: production
type: TTP
description: This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk
ransomware. The Ryuk Ransomware uses the Wake-on-Lan feature to turn on powered
off devices on a compromised network to have greater success encrypting them. This
is a high fidelity indicator of Ryuk ransomware executing on an endpoint. Upon triage,
isolate the endpoint. Additional file modification events will be within the users
profile (\appdata\roaming) and in public directories (users\public\). Review all
Scheduled Tasks on the isolated endpoint and across the fleet. Suspicious Scheduled
Tasks will include a path to a unknown binary and those endpoints should be isolated
until triaged.
data_source:
- Sysmon Event ID 1
search:
selection1:
CommandLine:
- '*8 LAN*'
- '*9 REP*'
condition: (selection1)
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node.
known_false_positives: Limited to no known false positives.
references:
- https://www.bleepingcomputer.com/news/security/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices/
- https://www.bleepingcomputer.com/news/security/ryuk-ransomware-now-self-spreads-to-other-windows-lan-devices/
- https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf
tags:
analytic_story:
- Ryuk Ransomware
asset_type: Endpoint
confidence: 90
impact: 70
message: A process $process_name$ with wake on LAN commandline $process$ in host
$dest$
mitre_attack_id:
- T1059
- T1059.003
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 63
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/ryuk/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog