Files
splunk-security_content/detections/endpoint/common_ransomware_notes.yml
2022-03-09 14:43:09 +01:00

75 lines
2.4 KiB
YAML

name: Common Ransomware Notes
id: ada0f478-84a8-4641-a3f1-d82362d6bd71
version: 4
date: '2020-11-09'
author: David Dorsey, Splunk
type: Hunting
datamodel:
- Endpoint
description: The search looks for files created with names matching those typically
used in ransomware notes that tell the victim how to get their data back.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path)
as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name | `drop_dm_object_name(Filesystem)`
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ransomware_notes`
| `common_ransomware_notes_filter`'
how_to_implement: You must be ingesting data that records file-system activity from
your hosts to populate the Endpoint Filesystem data-model node. This is typically
populated via endpoint detection-and-response product, such as Carbon Black, or
via other endpoint data sources, such as Sysmon. The data used for this search is
typically generated via logs that report file-system reads and writes.
known_false_positives: It's possible that a legitimate file could be created with
the same name used by ransomware note files.
references: []
tags:
Consequence: Data Destruction
analytic_story:
- SamSam Ransomware
- Ransomware
- Ryuk Ransomware
- Clop Ransomware
asset_type: Endpoint
cis20:
- CIS 8
confidence: 100
context:
- Source:Endpoint
- Stage:Execution
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/ransomware_notes/windows-sysmon.log
impact: 90
kill_chain_phases:
- Actions on Objectives
message: A file - $file_name$ was written to disk on endpoint $dest$ by user $user$,
this is indicative of a known ransomware note file and should be reviewed immediately.
mitre_attack_id:
- T1485
nist:
- PR.PT
- DE.CM
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: file_name
type: File Name
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.user
- Filesystem.dest
- Filesystem.file_path
- Filesystem.file_name
risk_score: 90
security_domain: endpoint