Files
splunk-security_content/detections/unusually_long_command_line___mltk.yml
Patrick Bareiss 729419b24d Updated searches
2020-05-25 11:06:36 +02:00

51 lines
2.7 KiB
YAML

name: Unusually Long Command Line - MLTK
id: 57edaefa-a73b-45e5-bbae-f39c1473f941
version: 1
date: '2019-05-08'
description: Command lines that are extremely long may be indicative of malicious
activity on your hosts. This search leverages the Machine Learning Toolkit (MLTK)
to help identify command lines with lengths that are unusual for a given user.
how_to_implement: You must be ingesting endpoint data that monitors command lines
and populates the Endpoint data model in the Processes node. The command-line arguments
are mapped to the "process" field in the Endpoint data model. In addition, MLTK
version >= 4.2 must be installed on your search heads, along with any required dependencies.
Finally, the support search "Baseline of Command Line Length - MLTK" must be executed
before this detection search, as it builds an ML model over the historical data
used by this search. It is important that this search is run in the same app context
as the associated support search, so that the model created by the support search
is available for use. You should periodically re-run the support search to rebuild
the model with the latest data available in your environment.
type: ESCU
references: []
author: Rico Valdez, Splunk
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name
Processes.process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)`| eval processlen=len(process) | search user!=unknown
| apply cmdline_pdfmodel threshold=0.01 | rename "IsOutlier(processlen)" as isOutlier
| search isOutlier > 0 | table firstTime lastTime user dest process_name process
processlen count | `unusually_long_command_line___mltk_filter`'
known_false_positives: Some legitimate applications use long command lines for installs
or updates. You should review identified command lines for legitimacy. You may modify
the first part of the search to omit legitimate command lines from consideration.
If you are seeing more results than desired, you may consider changing the value
of threshold in the search to a smaller value. You should also periodically re-run
the support search to re-build the ML model on the latest data. You may get unexpected
results if the user identified in the results is not present in the data used to
build the associated model.
tags:
analytics_story:
- Suspicious Command-Line Executions
- Unusual Processes
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
- Ransomware
kill_chain_phases:
- Actions on Objectives
cis20:
- CIS 8
nist:
- PR.PT
- DE.CM
security_domain: endpoint
asset_type: ''