Files
splunk-security_content/detections/endpoint/office_product_spawning_bitsadmin.yml
2024-06-26 14:41:53 +00:00

86 lines
3.8 KiB
YAML

name: Office Product Spawning BITSAdmin
id: e8c591f4-a6d7-11eb-8cf7-acde48001122
version: 6
date: '2024-05-11'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following analytic detects any Windows Office Product spawning `bitsadmin.exe`,
a behavior often associated with malware families like TA551 and IcedID. This detection
leverages data from Endpoint Detection and Response (EDR) agents, focusing on process
and parent process relationships. This activity is significant because `bitsadmin.exe`
is commonly used for malicious file transfers, potentially indicating a malware
infection. If confirmed malicious, this activity could allow attackers to download
additional payloads, escalate privileges, or establish persistence, leading to further
compromise of the affected system.
data_source:
- Sysmon EventID 1
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name
IN ("winword.exe","excel.exe","powerpnt.exe","mspub.exe","visio.exe","onenote.exe","onenotem.exe","onenoteviewer.exe","onenoteim.exe",
"msaccess.exe", "Graph.exe","winproj.exe") `process_bitsadmin` by Processes.dest
Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `office_product_spawning_bitsadmin_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
you must ingest logs that contain the process GUID, process name, and parent process.
Additionally, you must ingest complete command-line executions. These logs must
be processed using the appropriate Splunk Technology Add-ons that are specific to
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: No false positives known. Filter as needed.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1197/T1197.md
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
tags:
analytic_story:
- Spearphishing Attachments
- CVE-2023-36884 Office and Windows HTML RCE Vulnerability
asset_type: Endpoint
confidence: 90
impact: 70
message: office parent process $parent_process_name$ will execute a suspicious child
process $process_name$ with process id $process_id$ in host $dest$
mitre_attack_id:
- T1566
- T1566.001
observable:
- name: dest
type: Hostname
role:
- Victim
- name: process_name
type: Process
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
risk_score: 63
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon_macros.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog