mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
51 lines
2.7 KiB
YAML
51 lines
2.7 KiB
YAML
name: Unusually Long Command Line - MLTK
|
|
id: 57edaefa-a73b-45e5-bbae-f39c1473f941
|
|
version: 1
|
|
date: '2019-05-08'
|
|
description: Command lines that are extremely long may be indicative of malicious
|
|
activity on your hosts. This search leverages the Machine Learning Toolkit (MLTK)
|
|
to help identify command lines with lengths that are unusual for a given user.
|
|
how_to_implement: You must be ingesting endpoint data that monitors command lines
|
|
and populates the Endpoint data model in the Processes node. The command-line arguments
|
|
are mapped to the "process" field in the Endpoint data model. In addition, MLTK
|
|
version >= 4.2 must be installed on your search heads, along with any required dependencies.
|
|
Finally, the support search "Baseline of Command Line Length - MLTK" must be executed
|
|
before this detection search, as it builds an ML model over the historical data
|
|
used by this search. It is important that this search is run in the same app context
|
|
as the associated support search, so that the model created by the support search
|
|
is available for use. You should periodically re-run the support search to rebuild
|
|
the model with the latest data available in your environment.
|
|
type: ESCU
|
|
references: []
|
|
author: Rico Valdez, Splunk
|
|
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
|
as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name
|
|
Processes.process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
|
|
`security_content_ctime(lastTime)`| eval processlen=len(process) | search user!=unknown
|
|
| apply cmdline_pdfmodel threshold=0.01 | rename "IsOutlier(processlen)" as isOutlier
|
|
| search isOutlier > 0 | table firstTime lastTime user dest process_name process
|
|
processlen count | `unusually_long_command_line___mltk_filter`'
|
|
known_false_positives: Some legitimate applications use long command lines for installs
|
|
or updates. You should review identified command lines for legitimacy. You may modify
|
|
the first part of the search to omit legitimate command lines from consideration.
|
|
If you are seeing more results than desired, you may consider changing the value
|
|
of threshold in the search to a smaller value. You should also periodically re-run
|
|
the support search to re-build the ML model on the latest data. You may get unexpected
|
|
results if the user identified in the results is not present in the data used to
|
|
build the associated model.
|
|
tags:
|
|
analytics_story:
|
|
- Suspicious Command-Line Executions
|
|
- Unusual Processes
|
|
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
|
- Ransomware
|
|
kill_chain_phases:
|
|
- Actions on Objectives
|
|
cis20:
|
|
- CIS 8
|
|
nist:
|
|
- PR.PT
|
|
- DE.CM
|
|
security_domain: endpoint
|
|
asset_type: ''
|