Files
splunk-security_content/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml
T
P4T12ICK 7c134dbb5d WIP
2021-03-10 14:44:44 +01:00

60 lines
2.2 KiB
YAML

name: Malicious PowerShell Process With Obfuscation Techniques
id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4
version: 4
date: '2021-01-19'
author: David Dorsey, Splunk
type: batch
datamodel:
- Endpoint
description: This search looks for PowerShell processes launched with arguments that
have characters indicative of obfuscation on the command-line.
search: '| tstats `security_content_summariesonly` count values(Processes.process)
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe
by Processes.user Processes.process_name Processes.parent_process_name Processes.dest
Processes.process | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)`| eval num_obfuscation = (mvcount(split(process,"`"))-1)
+ (mvcount(split(process, "^"))-1) + (mvcount(split(process, "''"))-1) | `malicious_powershell_process_with_obfuscation_techniques_filter`
| search num_obfuscation > 10 '
how_to_implement: You must be ingesting data that records process activity from your
hosts to populate the Endpoint data model in the Processes node. You must also be
ingesting logs with both the process name and command line from your endpoints.
The command-line arguments are mapped to the "process" field in the Endpoint data
model.
known_false_positives: These characters might be legitimately on the command-line,
but it is not common.
references: []
tags:
analytic_story:
- Malicious PowerShell
asset_type: Endpoint
automated_detection_testing: passed
cis20:
- CIS 3
- CIS 7
- CIS 8
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/obfuscated_powershell/windows-sysmon.log
kill_chain_phases:
- Command and Control
- Actions on Objectives
mitre_attack_id:
- T1059.001
nist:
- PR.PT
- DE.CM
- PR.IP
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.parent_process
- Processes.process_name
- Processes.user
- Processes.parent_process_name
- Processes.dest
security_domain: endpoint