mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
87 lines
3.8 KiB
YAML
87 lines
3.8 KiB
YAML
name: Detect Exchange Web Shell
|
|
id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a
|
|
version: 4
|
|
date: '2022-09-30'
|
|
author: Michael Haag, Shannon Davis, David Dorsey, Splunk
|
|
status: production
|
|
type: TTP
|
|
description: 'The following query identifies suspicious .aspx created in 3 paths identified
|
|
by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM
|
|
group and recently disclosed vulnerablity named ProxyShell and ProxyNotShell. Paths
|
|
include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`.
|
|
Upon triage, the suspicious .aspx file will likely look obvious on the surface.
|
|
inspect the contents for script code inside. Identify additional log sources, IIS
|
|
included, to review source and other potential exploitation. It is often the case
|
|
that a particular threat is only applicable to a specific subset of systems in your
|
|
environment. Typically analytics to detect those threats are written without the
|
|
benefit of being able to only target those systems as well. Writing analytics against
|
|
all systems when those behaviors are limited to identifiable subsets of those systems
|
|
is suboptimal. Consider the case ProxyShell vulnerability on Microsoft Exchange
|
|
Servers. With asset information, a hunter can limit their analytics to systems that
|
|
have been identified as Exchange servers. A hunter may start with the theory that
|
|
the exchange server is communicating with new systems that it has not previously.
|
|
If this theory is run against all publicly facing systems, the amount of noise it
|
|
will generate will likely render this theory untenable. However, using the asset
|
|
information to limit this analytic to just the Exchange servers will reduce the
|
|
noise allowing the hunter to focus only on the systems where this behavioral change
|
|
is relevant.'
|
|
data_source:
|
|
- Sysmon Event ID 1
|
|
search:
|
|
selection1:
|
|
Image|endswith: System
|
|
condition: selection1
|
|
how_to_implement: To successfully implement this search you need to be ingesting information
|
|
on process that include the name of the process responsible for the changes from
|
|
your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
|
|
node.
|
|
known_false_positives: The query is structured in a way that `action` (read, create)
|
|
is not defined. Review the results of this query, filter, and tune as necessary.
|
|
It may be necessary to generate this query specific to your endpoint product.
|
|
references:
|
|
- https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv
|
|
- https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell
|
|
- https://www.youtube.com/watch?v=FC6iHw258RI
|
|
- https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do
|
|
tags:
|
|
analytic_story:
|
|
- HAFNIUM Group
|
|
- ProxyShell
|
|
- CISA AA22-257A
|
|
- ProxyNotShell
|
|
asset_type: Endpoint
|
|
confidence: 90
|
|
impact: 90
|
|
message: A file - $file_name$ was written to disk that is related to IIS exploitation
|
|
previously performed by HAFNIUM. Review further file modifications on endpoint
|
|
$dest$ by user $user$.
|
|
mitre_attack_id:
|
|
- T1505
|
|
- T1505.003
|
|
- T1190
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
- name: file_name
|
|
type: File Name
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
risk_score: 81
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: xmlwineventlog
|