mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
78 lines
3.9 KiB
YAML
78 lines
3.9 KiB
YAML
name: ProxyShell ProxyNotShell Behavior Detected
|
|
id: c32fab32-6aaf-492d-bfaf-acbed8e50cdf
|
|
version: 1
|
|
date: '2023-07-10'
|
|
author: Michael Haag, Splunk
|
|
status: production
|
|
type: Correlation
|
|
description: The following correlation will identify activity related to Windows Exchange
|
|
being actively exploited by adversaries related to ProxyShell or ProxyNotShell.
|
|
In addition, the analytic correlates post-exploitation Cobalt Strike analytic story.
|
|
Common post-exploitation behavior has been seen in the wild includes adversaries
|
|
running nltest, Cobalt Strike, Mimikatz and adding a new user. The correlation specifically
|
|
looks for 5 distinct analyticstories to trigger. Modify or tune as needed for your
|
|
organization. 5 analytics is an arbitrary number but was chosen to reduce the amount
|
|
of noise but also require the 2 analytic stories or a ProxyShell and CobaltStrike
|
|
to fire. Adversaries will exploit the vulnerable Exchange server, abuse SSRF, drop
|
|
a web shell, utilize the PowerShell Exchange modules and begin post-exploitation.
|
|
data_source: []
|
|
search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time)
|
|
as lastTime sum(All_Risk.calculated_risk_score) as risk_score, count(All_Risk.calculated_risk_score)
|
|
as risk_event_count, values(All_Risk.annotations.mitre_attack.mitre_tactic_id) as
|
|
annotations.mitre_attack.mitre_tactic_id, dc(All_Risk.annotations.mitre_attack.mitre_tactic_id)
|
|
as mitre_tactic_id_count, values(All_Risk.analyticstories) as analyticstories values(All_Risk.annotations.mitre_attack.mitre_technique_id)
|
|
as annotations.mitre_attack.mitre_technique_id, dc(All_Risk.annotations.mitre_attack.mitre_technique_id)
|
|
as mitre_technique_id_count, values(All_Risk.tag) as tag, values(source) as source,
|
|
dc(source) as source_count dc(All_Risk.analyticstories) as dc_analyticstories from
|
|
datamodel=Risk.All_Risk where All_Risk.analyticstories IN ("ProxyNotShell","ProxyShell")
|
|
OR (All_Risk.analyticstories IN ("ProxyNotShell","ProxyShell") AND All_Risk.analyticstories="Cobalt
|
|
Strike") All_Risk.risk_object_type="system" by _time span=1h All_Risk.risk_object
|
|
All_Risk.risk_object_type | `drop_dm_object_name(All_Risk)` | `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`| where source_count >=5 | `proxyshell_proxynotshell_behavior_detected_filter`'
|
|
how_to_implement: To implement this correlation, you will need to enable ProxyShell,
|
|
ProxyNotShell and Cobalt Strike analytic stories (the anaytics themselves) and ensure
|
|
proper data is being collected for Web and Endpoint datamodels. Run the correlation
|
|
rule seperately to validate it is not triggering too much or generating incorrectly.
|
|
Validate by running ProxyShell POC code and Cobalt Strike behavior.
|
|
known_false_positives: False positives will be limited, however tune or modify the
|
|
query as needed.
|
|
references:
|
|
- https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
|
|
- https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
|
|
tags:
|
|
analytic_story:
|
|
- ProxyShell
|
|
- BlackByte Ransomware
|
|
- ProxyNotShell
|
|
asset_type: Web Server
|
|
confidence: 90
|
|
impact: 90
|
|
message: ProxyShell or ProxyNotShell activity has been identified on $risk_object$.
|
|
mitre_attack_id:
|
|
- T1190
|
|
- T1133
|
|
observable:
|
|
- name: risk_object
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- All_Risk.analyticstories
|
|
- All_Risk.risk_object_type
|
|
- All_Risk.risk_object
|
|
- All_Risk.annotations.mitre_attack.mitre_tactic
|
|
- source
|
|
risk_score: 81
|
|
security_domain: network
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/proxyshell/proxyshell-risk.log
|
|
source: proxyshell
|
|
sourcetype: stash
|
|
update_timestamp: true
|