Files
splunk-security_content/detections/endpoint/potentially_malicious_code_on_commandline.yml
2024-06-26 14:41:53 +00:00

83 lines
3.7 KiB
YAML

name: Potentially malicious code on commandline
id: 9c53c446-757e-11ec-871d-acde48001122
version: 2
date: '2024-05-12'
author: Michael Hart, Splunk
status: production
type: Anomaly
description: The following analytic detects potentially malicious command lines using
a pretrained machine learning text classifier. It identifies unusual keyword combinations
in command lines, such as "streamreader," "webclient," "mutex," "function," and
"computehash," which are often associated with adversarial PowerShell code execution
for C2 communication. This detection leverages data from Endpoint Detection and
Response (EDR) agents, focusing on command lines longer than 200 characters. This
activity is significant as it can indicate an attempt to execute malicious scripts,
potentially leading to unauthorized code execution, data exfiltration, or further
system compromise.
data_source:
- Sysmon EventID 1
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name
Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` |
where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score`
| apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'',
process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits)
orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `potentially_malicious_code_on_commandline_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
you must ingest logs that contain the process GUID, process name, and parent process.
Additionally, you must ingest complete command-line executions. These logs must
be processed using the appropriate Splunk Technology Add-ons that are specific to
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: This model is an anomaly detector that identifies usage of
APIs and scripting constructs that are correllated with malicious activity. These
APIs and scripting constructs are part of the programming langauge and advanced
scripts may generate false positives.
references:
- https://attack.mitre.org/techniques/T1059/003/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
tags:
analytic_story:
- Suspicious Command-Line Executions
asset_type: Endpoint
confidence: 20
impact: 60
message: Unusual command-line execution with command line length greater than 200
found on $dest$ with commandline value - [$process$]
mitre_attack_id:
- T1059.003
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.parent_process_name
- Processes.process_name
- Processes.parent_process
- Processes.user
- Processes.dest
risk_score: 12
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog