Files
splunk-security_content/detections/endpoint/excessive_usage_of_taskkill.yml
T
2023-03-03 12:40:16 +01:00

76 lines
2.6 KiB
YAML

name: Excessive Usage Of Taskkill
id: fe5bca48-accb-11eb-a67c-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
description: This analytic identifies excessive usage of `taskkill.exe` application.
This application is commonly used by adversaries to evade detections by killing
security product processes or even other processes to evade detection.
data_source:
- Sysmon Event ID 1
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "taskkill.exe" by
Processes.parent_process_name Processes.process_name Processes.dest Processes.user
_time span=1m | where count >=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_usage_of_taskkill_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used.
known_false_positives: Unknown. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
- https://www.joesandbox.com/analysis/702680/0/html
tags:
analytic_story:
- XMRig
- Azorult
- CISA AA22-264A
- AgentTesla
- CISA AA22-277A
asset_type: Endpoint
confidence: 70
impact: 40
message: Excessive usage of taskkill.exe with process id $process_id$ (more than
10 within 1m) has been detected on $dest$ with a parent process of $parent_process_name$.
mitre_attack_id:
- T1562.001
- T1562
observable:
- name: dest
type: Endpoint
role:
- Victim
- name: dest
type: Endpoint
role:
- Victim
- name: parent_process_name
type: Process Name
role:
- Parent Process
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process
- Processes.process_id
risk_score: 28
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog