mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
113 lines
4.5 KiB
Markdown
113 lines
4.5 KiB
Markdown
---
|
|
title: "GetDomainController with PowerShell"
|
|
excerpt: "Remote System Discovery"
|
|
categories:
|
|
- Endpoint
|
|
last_modified_at: 2021-09-07
|
|
toc: true
|
|
toc_label: ""
|
|
tags:
|
|
- Remote System Discovery
|
|
- Discovery
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
- Endpoint
|
|
---
|
|
|
|
|
|
|
|
[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success}
|
|
|
|
#### Description
|
|
|
|
This analytic looks for the execution of `powershell.exe` with command-line arguments utilized to discover remote systems. `Get-DomainController` is part of PowerView, a PowerShell tool used to perform enumeration on Windows domains. Red Teams and adversaries alike may leverage PowerView to enumerate domain groups for situational awareness and Active Directory Discovery.
|
|
|
|
- **Type**: [Hunting](https://github.com/splunk/security_content/wiki/Detection-Analytic-Types)
|
|
- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
|
|
- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint)
|
|
- **Last Updated**: 2021-09-07
|
|
- **Author**: Mauricio Velazco, Splunk
|
|
- **ID**: 868ee0e4-52ab-484a-833a-6d85b7c028d0
|
|
|
|
|
|
#### [ATT&CK](https://attack.mitre.org/)
|
|
|
|
| ID | Technique | Tactic |
|
|
| -------------- | ---------------- |-------------------- |
|
|
| [T1018](https://attack.mitre.org/techniques/T1018/) | Remote System Discovery | Discovery |
|
|
|
|
#### Search
|
|
|
|
```
|
|
|
|
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name="powershell.exe") (Processes.process=*Get-DomainController*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
|
| `drop_dm_object_name(Processes)`
|
|
| `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`
|
|
| `getdomaincontroller_with_powershell_filter`
|
|
```
|
|
|
|
#### Macros
|
|
The SPL above uses the following Macros:
|
|
* [security_content_ctime](https://github.com/splunk/security_content/blob/develop/macros/security_content_ctime.yml)
|
|
* [security_content_summariesonly](https://github.com/splunk/security_content/blob/develop/macros/security_content_summariesonly.yml)
|
|
|
|
Note that `getdomaincontroller_with_powershell_filter` is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.
|
|
|
|
#### Required field
|
|
* Processes.dest
|
|
* Processes.user
|
|
* Processes.parent_process_name
|
|
* Processes.parent_process
|
|
* Processes.original_file_name
|
|
* Processes.process_name
|
|
* Processes.process
|
|
* Processes.process_id
|
|
* Processes.parent_process_path
|
|
* Processes.process_path
|
|
* Processes.parent_process_id
|
|
|
|
|
|
#### How To Implement
|
|
To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node.
|
|
|
|
#### Known False Positives
|
|
Administrators or power users may use PowerView for troubleshooting.
|
|
|
|
#### Associated Analytic story
|
|
* [Active Directory Discovery](/stories/active_directory_discovery)
|
|
|
|
|
|
#### Kill Chain Phase
|
|
* Reconnaissance
|
|
|
|
|
|
|
|
#### RBA
|
|
|
|
| Risk Score | Impact | Confidence | Message |
|
|
| ----------- | ----------- |--------------|--------------|
|
|
| 24.0 | 30 | 80 | Remote system discovery using PowerView on $dest$ by $user$ |
|
|
|
|
|
|
Note that risk score is calculated base on the following formula: `(Impact * Confidence)/100`
|
|
|
|
|
|
|
|
#### Reference
|
|
|
|
* [https://attack.mitre.org/techniques/T1018/](https://attack.mitre.org/techniques/T1018/)
|
|
* [https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/](https://powersploit.readthedocs.io/en/latest/Recon/Get-DomainController/)
|
|
|
|
|
|
|
|
#### Test Dataset
|
|
Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui).
|
|
Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server)
|
|
|
|
* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1018/AD_discovery/windows-sysmon.log)
|
|
|
|
|
|
|
|
[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/getdomaincontroller_with_powershell.yml) \| *version*: **1** |