Files
splunk-security_content/dev/endpoint/detect_exchange_web_shell.yml
T
2023-01-20 13:24:15 +01:00

87 lines
3.8 KiB
YAML

name: Detect Exchange Web Shell
id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a
version: 4
date: '2022-09-30'
author: Michael Haag, Shannon Davis, David Dorsey, Splunk
status: production
type: TTP
description: 'The following query identifies suspicious .aspx created in 3 paths identified
by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM
group and recently disclosed vulnerablity named ProxyShell and ProxyNotShell. Paths
include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`.
Upon triage, the suspicious .aspx file will likely look obvious on the surface.
inspect the contents for script code inside. Identify additional log sources, IIS
included, to review source and other potential exploitation. It is often the case
that a particular threat is only applicable to a specific subset of systems in your
environment. Typically analytics to detect those threats are written without the
benefit of being able to only target those systems as well. Writing analytics against
all systems when those behaviors are limited to identifiable subsets of those systems
is suboptimal. Consider the case ProxyShell vulnerability on Microsoft Exchange
Servers. With asset information, a hunter can limit their analytics to systems that
have been identified as Exchange servers. A hunter may start with the theory that
the exchange server is communicating with new systems that it has not previously.
If this theory is run against all publicly facing systems, the amount of noise it
will generate will likely render this theory untenable. However, using the asset
information to limit this analytic to just the Exchange servers will reduce the
noise allowing the hunter to focus only on the systems where this behavioral change
is relevant.'
data_source:
- Sysmon Event ID 1
search:
selection1:
Image|endswith: System
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem`
node.
known_false_positives: The query is structured in a way that `action` (read, create)
is not defined. Review the results of this query, filter, and tune as necessary.
It may be necessary to generate this query specific to your endpoint product.
references:
- https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv
- https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell
- https://www.youtube.com/watch?v=FC6iHw258RI
- https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do
tags:
analytic_story:
- HAFNIUM Group
- ProxyShell
- CISA AA22-257A
- ProxyNotShell
asset_type: Endpoint
confidence: 90
impact: 90
message: A file - $file_name$ was written to disk that is related to IIS exploitation
previously performed by HAFNIUM. Review further file modifications on endpoint
$dest$ by user $user$.
mitre_attack_id:
- T1505
- T1505.003
- T1190
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: file_name
type: File Name
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 81
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog