Files
splunk-security_content/detections/wmi_process_launch.yml
2019-12-11 15:14:49 -05:00

108 lines
3.5 KiB
YAML

asset_type: Endpoint
confidence: medium
creation_date: '2018-10-23'
data_metadata:
data_models:
- Endpoint
data_source:
- Endpoint Intel
providing_technologies:
- Carbon Black Response
- Sysmon
- Tanium
- Ziften
description: This search looks for processes launched via WMI.
detect:
splunk:
correlation_rule:
notable:
nes_fields: dest, user, process
rule_description: This search looks for child processes of WmiPrvSE.exe, which
indicates that a process was launched via WMI.
rule_title: Process launched via WMI on $dest$
risk:
risk_object: dest
risk_object_type:
- system
risk_score: 70
schedule:
cron_schedule: 0 * * * *
earliest_time: -70m@m
latest_time: -10m@m
search: '| tstats `security_content_summariesonly` count values(Processes.process) as process
min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
where Processes.parent_process_name = *WmiPrvSE.exe by Processes.user Processes.dest
Processes.process_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)`'
suppress:
suppress_fields: dest, user
suppress_period: 28800s
eli5: Attackers are increasingly abusing Windows Management Infrastructure (WMI) for
stealth, persistence, lateral movement, or just to leverage its functionality. This
search looks for processes launched via WMI, either remotely or locally, by looking
for processes launched by WmiPrvSE.exe, which is the process WMI uses to execute
new processes and commands.
entities:
- dest
how_to_implement: You must be ingesting endpoint data that tracks process activity,
including parent-child relationships from your endpoints to populate the Endpoint
data model in the Processes node. The command-line arguments are mapped to the "process"
field in the Endpoint data model.
id: 24869767-8579-485d-9a4f-d9ddfd8f0cac
investigations:
- id: 155e0571-7db6-42f2-aa62-9a3a4cf35c94
name: Get Sysmon WMI Activity for Host
type: splunk
- id: bc91a8cf-35e7-4bb2-8140-e756cc06fd76
name: Get Authentication Logs For Endpoint
type: splunk
- id: fdcfb369-1725-4c24-824a-22972d7f0d55
name: Get Risk Modifiers For User
type: splunk
- id: bc91a8cf-35e7-4bb2-8140-e756cc06fd71
name: Get Process Info
type: splunk
- id: 3d6c3213-5fff-4a1e-b57d-b24c262171e7
name: Get Notable History
type: splunk
- id: f3fb4d1b-5f33-4b01-b541-c7af9534c242
name: Get Notable Info
type: splunk
- id: fdcfb369-1725-4c24-824a-22972d7f0d65
name: Get Risk Modifiers For Endpoint
type: splunk
- id: bc91a8cf-35e7-4bb2-8140-e756cc06fd74
name: Get User Information from Identity Table
type: splunk
known_false_positives: Although unlikely, administrators may use wmi to execute commands
for legitimate purposes.
maintainers:
- company: Splunk
email: rvaldez@splunk.com
name: Rico Valdez
mappings:
cis20:
- CIS 3
- CIS 5
kill_chain_phases:
- Actions on Objectives
mitre_attack:
- Execution
- Windows Management Instrumentation
nist:
- PR.PT
- PR.AT
- PR.AC
- PR.IP
modification_date: '2019-02-28'
name: Process Execution via WMI
original_authors:
- company: Splunk
email: rvaldez@splunk.com
name: Rico Valdez
references: []
security_domain: endpoint
spec_version: 2
type: splunk
version: '2.0'