Files
splunk-security_content/detections/endpoint/detect_mshta_inline_hta_execution.yml
T
mhaag-spl f3d274c0f8 ID changes
ID changes and a test file needed moved
2021-01-20 14:45:27 -07:00

46 lines
2.2 KiB
YAML

name: Detect mshta inline hta execution
id: a0873b32-5b68-11eb-ae93-0242ac130002
version: 5
date: '2021-01-20'
description: The following analytic identifies "mshta.exe" execution with inline
protocol handlers. "JavaScript", "VBScript", and "About" are the only supported
options when invoking HTA content directly on the command-line. The search will
return the first time and last time these command-line arguments were used for
these executions, as well as the target system, the user, process "mshta.exe"
and its parent process.
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node.
type: ESCU
references:
- https://github.com/redcanaryco/AtomicTestHarnesses
- https://redcanary.com/blog/introducing-atomictestharnesses/
- https://docs.microsoft.com/en-us/windows/win32/search/-search-3x-wds-extidx-prot-implementing
author: Bhavin Patel, Michael Haag, Splunk
search: '| tstats `security_content_summariesonly` count values(Processes.process)
as process values(Processes.parent_process) as parent_process min(_time) as firstTime
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe
(Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user
Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `detect_mshta_inline_hta_execution_filter`'
known_false_positives: Although unlikely, some legitimate applications may exhibit
this behavior, triggering a false positive.
tags:
analytics_story:
- Suspicious MSHTA Activity
mitre_attack_id:
- T1218.005
kill_chain_phases:
- Exploitation
cis20:
- CIS 8
nist:
- PR.PT
- DE.CM
security_domain: endpoint
asset_type: Endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log