mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
87 lines
3.5 KiB
YAML
87 lines
3.5 KiB
YAML
name: Detect Certify Command Line Arguments
|
|
id: e6d2dc61-a8b9-4b03-906c-da0ca75d71b8
|
|
version: 2
|
|
date: '2024-05-25'
|
|
author: Steven Dick
|
|
status: production
|
|
type: TTP
|
|
description: The following analytic detects the use of Certify or Certipy tools to
|
|
enumerate Active Directory Certificate Services (AD CS) environments. It leverages
|
|
Endpoint Detection and Response (EDR) data, focusing on specific command-line arguments
|
|
associated with these tools. This activity is significant because it indicates potential
|
|
reconnaissance or exploitation attempts targeting AD CS, which could lead to unauthorized
|
|
access or privilege escalation. If confirmed malicious, attackers could gain insights
|
|
into the AD CS infrastructure, potentially compromising sensitive certificates and
|
|
escalating their privileges within the network.
|
|
data_source:
|
|
- Sysmon EventID 1
|
|
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
|
as lastTime from datamodel=Endpoint.Processes where Processes.process IN ("* find
|
|
*","* auth *","* request *","* req *","* download *",) AND Processes.process IN
|
|
("* /vulnerable*","* /enrolleeSuppliesSubject *","* /json /outfile*","* /ca*", "*
|
|
-username *","* -u *") by Processes.dest Processes.user Processes.parent_process
|
|
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
|
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
|
|
`detect_certify_command_line_arguments_filter`'
|
|
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
|
and Response (EDR) agents. These agents are designed to provide security-related
|
|
telemetry from the endpoints where the agent is installed. To implement this search,
|
|
you must ingest logs that contain the process GUID, process name, and parent process.
|
|
Additionally, you must ingest complete command-line executions. These logs must
|
|
be processed using the appropriate Splunk Technology Add-ons that are specific to
|
|
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
|
|
data model. Use the Splunk Common Information Model (CIM) to normalize the field
|
|
names and speed up the data modeling process.
|
|
known_false_positives: Unknown
|
|
references:
|
|
- https://github.com/GhostPack/Certify
|
|
- https://github.com/ly4k/Certipy
|
|
- https://specterops.io/wp-content/uploads/sites/3/2022/06/Certified_Pre-Owned.pdf
|
|
tags:
|
|
analytic_story:
|
|
- Windows Certificate Services
|
|
- Ingress Tool Transfer
|
|
asset_type: Endpoint
|
|
confidence: 90
|
|
impact: 100
|
|
message: Certify/Certipy arguments detected on $dest$.
|
|
mitre_attack_id:
|
|
- T1649
|
|
- T1105
|
|
observable:
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
- name: process_name
|
|
type: Process
|
|
role:
|
|
- Attacker
|
|
- name: process_name
|
|
type: Process Name
|
|
role:
|
|
- Attacker
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- Processes.dest
|
|
- Processes.user
|
|
- Processes.parent_process
|
|
- Processes.process_name
|
|
- Processes.process
|
|
- Processes.process_id
|
|
- Processes.parent_process_id
|
|
risk_score: 90
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data:
|
|
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1649/certify_abuse/certify_esc1_abuse_sysmon.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: xmlwineventlog
|
|
update_timestamp: true
|