Files
splunk-security_content/dev/endpoint/windows_process_injection_wermgr_child_process.yml
2023-01-20 13:24:15 +01:00

56 lines
2.0 KiB
YAML

name: Windows Process Injection Wermgr Child Process
id: 360ae6b0-38b5-4328-9e2b-bc9436cddb17
version: 1
date: '2022-10-27'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
description: The following analytic identifies a suspicious wermgr.exe parent process
having a child process not related to error, fault or windows werfault event. This
technique was seen in Qakbot malware where it inject its malicious code in wermgr
to evade detections and hide from the analyst to execute its recon and its malicious
behavior. This Anomaly detection can be a good pivot to start investigating a possible
qakbot infection in the network. The Wermgr.exe process is not known to have other
child processes aside from itself or werfault.exe
data_source:
- Sysmon Event ID 1
search:
selection1:
ParentImage: wermgr.exe
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: unknown
references:
- https://twitter.com/pr0xylife/status/1585612370441031680?s=46&t=Dc3CJi4AnM-8rNoacLbScg
tags:
analytic_story:
- Qakbot
asset_type: Endpoint
confidence: 70
impact: 80
message: wermgr parent process has a child process $process_name$ in $dest$
mitre_attack_id:
- T1055
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 56
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_wermgr/sysmon_wermgr.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true