Files
splunk-security_content/detections/endpoint/potentially_malicious_code_on_commandline.yml
2023-09-15 10:58:38 -07:00

82 lines
3.9 KiB
YAML

name: Potentially malicious code on commandline
id: 9c53c446-757e-11ec-871d-acde48001122
version: 1
date: '2022-01-14'
author: Michael Hart, Splunk
status: production
type: Anomaly
description: The following analytic uses a pretrained machine learning text classifier
to detect potentially malicious commandlines. The model identifies unusual combinations
of keywords found in samples of commandlines where adversaries executed powershell
code, primarily for C2 communication. For example, adversaries will leverage IO
capabilities such as "streamreader" and "webclient", threading capabilties such
as "mutex" locks, programmatic constructs like "function" and "catch", and cryptographic
operations like "computehash". Although observing one of these keywords in a commandline
script is possible, combinations of keywords observed in attack data are not typically
found in normal usage of the commandline. The model will output a score where all
values above zero are suspicious, anything greater than one particularly so.
data_source: []
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel="Endpoint.Processes" by Processes.parent_process_name
Processes.process_name Processes.process Processes.user Processes.dest | `drop_dm_object_name(Processes)` |
where len(process) > 200 | `potentially_malicious_code_on_cmdline_tokenize_score`
| apply unusual_commandline_detection | eval score=''predicted(unusual_cmdline_logits)'',
process=orig_process | fields - unusual_cmdline* predicted(unusual_cmdline_logits)
orig_process | where score > 0.5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `potentially_malicious_code_on_commandline_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
and Response (EDR) agents. These agents are designed to provide security-related
telemetry from the endpoints where the agent is installed. To implement this search,
you must ingest logs that contain the process GUID, process name, and parent process.
Additionally, you must ingest complete command-line executions. These logs must
be processed using the appropriate Splunk Technology Add-ons that are specific to
the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint`
data model. Use the Splunk Common Information Model (CIM) to normalize the field
names and speed up the data modeling process.
known_false_positives: This model is an anomaly detector that identifies usage of
APIs and scripting constructs that are correllated with malicious activity. These
APIs and scripting constructs are part of the programming langauge and advanced
scripts may generate false positives.
references:
- https://attack.mitre.org/techniques/T1059/003/
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
tags:
analytic_story:
- Suspicious Command-Line Executions
asset_type: Endpoint
confidence: 20
impact: 60
message: Unusual command-line execution with hallmarks of malicious activity run
by $user$ found on $dest$ with commandline $process$
mitre_attack_id:
- T1059.003
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.parent_process_name
- Processes.process_name
- Processes.parent_process
- Processes.user
- Processes.dest
risk_score: 12
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/malicious_cmd_line_samples/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog