Files
splunk-security_content/dev/endpoint/screensaver_event_trigger_execution.yml
2023-01-20 13:24:15 +01:00

64 lines
2.3 KiB
YAML

name: Screensaver Event Trigger Execution
id: 58cea3ec-1f6d-11ec-8560-acde48001122
version: 1
date: '2021-09-27'
author: Teoderick Contreras, Splunk
status: production
type: TTP
description: This analytic is developed to detect possible event trigger execution
through screensaver registry entry modification for persistence or privilege escalation.
This technique was seen in several APT and malware where they put the malicious
payload path to the SCRNSAVE.EXE registry key to redirect the execution to their
malicious payload path. This TTP is a good indicator that some attacker may modify
this entry for their persistence and privilege escalation.
data_source:
- Sysmon Event ID 13
search:
selection1:
TargetObject: '*\\Control Panel\\Desktop\\SCRNSAVE.EXE*'
condition: (selection1)
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
product, such as Carbon Black or endpoint data sources, such as Sysmon. The data
used for this search is typically generated via logs that report reads and writes
to the registry.
known_false_positives: unknown
references:
- https://attack.mitre.org/techniques/T1546/002/
- https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver
tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
asset_type: Endpoint
confidence: 90
impact: 80
message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$
mitre_attack_id:
- T1546
- T1546.002
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 72
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog