5.6 KiB
Detection Schema Schema
http://example.com/example.json
schema for detections
| Abstract | Extensible | Status | Identifiable | Custom Properties | Additional Properties | Defined In |
|---|---|---|---|---|---|---|
| Can be instantiated | No | Experimental | No | Forbidden | Permitted |
Detection Schema Properties
| Property | Type | Required | Nullable | Default | Defined by |
|---|---|---|---|---|---|
| author | string |
Required | No | "" |
Detection Schema (this schema) |
| date | string |
Required | No | "" |
Detection Schema (this schema) |
| description | string |
Required | No | "" |
Detection Schema (this schema) |
| how_to_implement | string |
Optional | No | "" |
Detection Schema (this schema) |
| id | string |
Required | No | "" |
Detection Schema (this schema) |
| known_false_positives | string |
Required | No | "" |
Detection Schema (this schema) |
| name | string |
Required | No | "" |
Detection Schema (this schema) |
| references | string[] |
Optional | No | [] |
Detection Schema (this schema) |
| search | string |
Required | No | "" |
Detection Schema (this schema) |
| tags | object |
Required | No | {} |
Detection Schema (this schema) |
| type | string |
Required | No | "" |
Detection Schema (this schema) |
| version | integer |
Required | No | 0 |
Detection Schema (this schema) |
* |
any | Additional | Yes | this schema allows additional properties |
author
Author of the detection
author
- is required
- type:
string - default:
"" - defined in this schema
author Type
string
author Example
"Patrick Bareiss, Splunk"
date
date of creation or modification, format yyyy-mm-dd
date
- is required
- type:
string - default:
"" - defined in this schema
date Type
string
date Example
"2019-12-06"
description
A detailed description of the detection
description
- is required
- type:
string - default:
"" - defined in this schema
description Type
string
description Example
"dbgcore.dll is a specifc DLL for Windows core debugging. It is used to obtain a memory dump of a process. This search detects the usage of this DLL for creating a memory dump of LSASS process. Memory dumps of the LSASS process can be created with tools such as Windows Task Manager or procdump."
how_to_implement
information about how to implement. Only needed for non standard implementations.
how_to_implement
- is optional
- type:
string - default:
"" - defined in this schema
how_to_implement Type
string
how_to_implement Example
"This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe."
id
UUID as unique identifier
id
- is required
- type:
string - default:
"" - defined in this schema
id Type
string
id Example
"fb4c31b0-13e8-4155-8aa5-24de4b8d6717"
known_false_positives
known false postives
known_false_positives
- is required
- type:
string - default:
"" - defined in this schema
known_false_positives Type
string
known_false_positives Example
"Administrators can create memory dumps for debugging purposes, but memory dumps of the LSASS process would be unusual."
name
Name of detection
name
- is required
- type:
string - default:
"" - defined in this schema
name Type
string
name Example
"Access LSASS Memory for Dump Creation"
references
A list of references for this detection
references
-
is optional
-
type:
string[] -
default:
[] -
defined in this schema
references Type
Array type: string[]
All items must be of the type:
string
An explanation about the purpose of this instance.
references Example
[
"https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf"
]
search
The Splunk search for the detection
search
- is required
- type:
string - default:
"" - defined in this schema
search Type
string
search Example
"`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR CallTrace=*dbghelp.dll* | stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, TargetProcessId, SourceImage, SourceProcessId | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `access_lsass_memory_for_dump_creation_filter`"
tags
An array of key value pairs for tagging
tags
- is required
- type:
object - default:
{} - defined in this schema
tags Type
object with following properties:
| Property | Type | Required |
|---|
tags Example
{
"analytics_story": "credential_dumping",
"custom_key": "custom_value"
}
type
type of detection
type
- is required
- type:
string - default:
"" - defined in this schema
type Type
string
type Example
"ESCU"
version
version of detection, e.g. 1 or 2 ...
version
- is required
- type:
integer - default:
0 - defined in this schema
version Type
integer
version Example
2