Files
splunk-security_content/dev/endpoint/windows_mimikatz_binary_execution.yml
T
Michael Haag ec897a5cbb more
2023-05-25 06:07:25 -06:00

77 lines
2.9 KiB
YAML

name: Windows Mimikatz Binary Execution
id: a9e0d6d3-9676-4e26-994d-4e0406bb4467
version: 1
date: '2022-11-16'
author: Michael Haag, Splunk
status: production
type: TTP
description: As simple as it sounds, this analytic identifies when the native mimikatz.exe
binary executes on Windows. It does look for the original file name as well, just
in case the binary is renamed. Adversaries sometimes bring in the default binary
and run it directly. Benjamin Delpy originally created Mimikatz as a proof of concept
to show Microsoft that its authentication protocols were vulnerable to an attack.
Instead, he inadvertently created one of the most widely used and downloaded threat
actor tools of the past 20 years. Mimikatz is an open-source application that allows
users to view and save authentication credentials such as Kerberos tickets.
data_source:
- Sysmon Event ID 1
search:
selection1:
OriginalFileName: mimikatz.exe
selection2:
Image|endswith: mimikatz.exe
condition: (selection1 or selection2)
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited as this is directly looking
for Mimikatz, the credential dumping utility.
references:
- https://www.cisa.gov/uscert/sites/default/files/publications/aa22-320a_joint_csa_iranian_government-sponsored_apt_actors_compromise_federal%20network_deploy_crypto%20miner_credential_harvester.pdf
- https://www.varonis.com/blog/what-is-mimikatz
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
tags:
analytic_story:
- Credential Dumping
- CISA AA22-320A
- Volt Typhoon
asset_type: Endpoint
confidence: 100
impact: 100
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$ attempting dump credentials.
mitre_attack_id:
- T1003
observable:
- name: user
type: User
role:
- Victim
- name: Computer
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 100
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/mimikatzwindows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true