Files
splunk-security_content/detections/endpoint/exchange_powershell_module_usage.yml
T
2024-06-26 14:41:53 +00:00

78 lines
3.5 KiB
YAML

name: Exchange PowerShell Module Usage
id: 2d10095e-05ae-11ec-8fdf-acde48001122
version: 6
date: '2024-05-31'
author: Michael Haag, Splunk
status: production
type: TTP
description: 'The following analytic detects the usage of specific Exchange PowerShell
modules, such as New-MailboxExportRequest, New-ManagementRoleAssignment, New-MailboxSearch,
and Get-Recipient. It leverages PowerShell Script Block Logging (EventCode 4104)
to identify these commands. This activity is significant because these modules can
be exploited by adversaries who have gained access via ProxyShell or ProxyNotShell
vulnerabilities. If confirmed malicious, attackers could export mailbox contents,
assign management roles, conduct mailbox searches, or view recipient objects, potentially
leading to data exfiltration, privilege escalation, or unauthorized access to sensitive
information.'
data_source:
- Powershell Script Block Logging 4104
search: '`powershell` EventCode=4104 ScriptBlockText IN ("*New-MailboxExportRequest*",
"*New-ManagementRoleAssignment*", "*New-MailboxSearch*", "*Get-Recipient*", "Search-Mailbox")
| stats count min(_time) as firstTime max(_time) as lastTime by Opcode Computer
UserID EventCode ScriptBlockText | rename Computer as dest |rename UserID as user
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `exchange_powershell_module_usage_filter`'
how_to_implement: To successfully implement this analytic, you will need to enable
PowerShell Script Block Logging on some or all endpoints. Additional setup here
https://docs.splunk.com/Documentation/UBA/5.0.4.1/GetDataIn/AddPowerShell#Configure_module_logging_for_PowerShell.
known_false_positives: Administrators or power users may use this PowerShell commandlet
for troubleshooting.
references:
- https://docs.microsoft.com/en-us/powershell/module/exchange/new-mailboxexportrequest?view=exchange-ps
- https://docs.microsoft.com/en-us/powershell/module/exchange/new-managementroleassignment?view=exchange-ps
- https://blog.orange.tw/2021/08/proxyshell-a-new-attack-surface-on-ms-exchange-part-3.html
- https://www.zerodayinitiative.com/blog/2021/8/17/from-pwn2own-2021-a-new-attack-surface-on-microsoft-exchange-proxyshell
- https://thedfirreport.com/2021/11/15/exchange-exploit-leads-to-domain-wide-ransomware/
- https://www.cisa.gov/uscert/ncas/alerts/aa22-264a
- https://learn.microsoft.com/en-us/powershell/module/exchange/new-mailboxsearch?view=exchange-ps
- https://learn.microsoft.com/en-us/powershell/module/exchange/get-recipient?view=exchange-ps
- https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
tags:
analytic_story:
- ProxyNotShell
- CISA AA22-277A
- ProxyShell
- BlackByte Ransomware
- CISA AA22-264A
asset_type: Endpoint
confidence: 80
impact: 40
message: Suspicious Exchange PowerShell module usaged was identified on $dest$.
mitre_attack_id:
- T1059
- T1059.001
observable:
- name: dest
type: Endpoint
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- ScriptBlockText
- Opcode
- Computer
- UserID
- EventCode
risk_score: 32
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/exchange/windows-powershell.log
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: XmlWinEventLog