Files
splunk-security_content/detections/remote_wmi_command_attempt.yml
2019-12-11 15:14:49 -05:00

111 lines
3.6 KiB
YAML

asset_type: Endpoint
confidence: medium
creation_date: '2017-01-13'
data_metadata:
data_models:
- Endpoint
data_source:
- Endpoint Intel
providing_technologies:
- Carbon Black Response
- CrowdStrike Falcon
- Sysmon
- Tanium
- Ziften
description: This search looks for wmic.exe being launched with parameters to operate
on remote systems.
detect:
splunk:
correlation_rule:
notable:
nes_fields: dest,user,process_name
rule_description: This search looks for wmic.exe being launched with parameters
to operate on remote systems.
rule_title: Endpoint - Remote WMI command attempt
risk:
risk_object: dest
risk_object_type:
- system
risk_score: 30
schedule:
cron_schedule: 50 * * * *
earliest_time: -70m@m
latest_time: -10m@m
search: '| tstats `security_content_summariesonly` count values(Processes.process) as process
values(Processes.parent_process) as parent_process min(_time) as firstTime
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe AND
Processes.process= */node* by Processes.user Processes.process_name Processes.parent_process_name
Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`'
suppress:
suppress_fields: dest,user,process_name
suppress_period: 28800s
eli5: Many a times, attackers leverage native Windows utilities that are designed
to help administrators better manage their systems, infrastructure, and auditing,
but are instead leveraged for malicious purposes. In this case, we are looking for
instances of wmic.exe being run with various parameters that are not typically used
by administrators.
entities:
- dest
how_to_implement: You must be ingesting data that records process activity from your
hosts to populate the Endpoint data model in the Processes node. You must also be
ingesting logs with both the process name and command line from your endpoints.
The command-line arguments are mapped to the "process" field in the Endpoint data
model.
id: 272df6de-61f1-4784-877c-1fbc3e2d0838
investigations:
- id: 155e0571-7db6-42f2-aa62-9a3a4cf35c94
name: Get Sysmon WMI Activity for Host
type: splunk
- id: bc91a8cf-35e7-4bb2-8140-e756cc06fd76
name: Get Authentication Logs For Endpoint
type: splunk
- id: fdcfb369-1725-4c24-824a-22972d7f0d55
name: Get Risk Modifiers For User
type: splunk
- id: bc91a8cf-35e7-4bb2-8140-e756cc06fd71
name: Get Process Info
type: splunk
- id: 3d6c3213-5fff-4a1e-b57d-b24c262171e7
name: Get Notable History
type: splunk
- id: f3fb4d1b-5f33-4b01-b541-c7af9534c242
name: Get Notable Info
type: splunk
- id: fdcfb369-1725-4c24-824a-22972d7f0d65
name: Get Risk Modifiers For Endpoint
type: splunk
- id: bc91a8cf-35e7-4bb2-8140-e756cc06fd74
name: Get User Information from Identity Table
type: splunk
known_false_positives: Administrators may use this legitimately to gather info from
remote systems.
maintainers:
- company: Splunk
email: rvaldez@splunk.com
name: Rico Valdez
mappings:
cis20:
- CIS 3
- CIS 5
kill_chain_phases:
- Actions on Objectives
mitre_attack:
- Execution
- Windows Management Instrumentation
nist:
- PR.PT
- PR.AT
- PR.AC
- PR.IP
modification_date: '2018-12-03'
name: Remote WMI Command Attempt
original_authors:
- company: Splunk
email: rvaldez@splunk.com
name: Rico Valdez
references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'