Files
splunk-security_content/dev/endpoint/excel_spawning_powershell.yml
T
2023-01-23 09:38:17 +01:00

84 lines
2.7 KiB
YAML

name: Excel Spawning PowerShell
id: 42d40a22-9be3-11eb-8f08-acde48001122
version: 1
date: '2021-04-12'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following detection identifies Microsoft Excel spawning PowerShell.
Typically, this is not common behavior and not default with Excel.exe. Excel.exe
will generally be found in the following path `C:\Program Files\Microsoft Office\root\Office16`
(version will vary). PowerShell spawning from Excel.exe is common for a spearphishing
attachment and is actively used. Albeit, the command executed will most likely be
encoded and captured via another detection. During triage, review parallel processes
and identify any files that may have been written.
data_source:
- Sysmon Event ID 1
search:
selection1:
ParentImage: excel.exe
selection2:
OriginalFileName: pwsh.dll
selection3:
Image|endswith:
- pwsh.exe
- sqlps.exe
- sqltoolsps.exe
- powershell.exe
- powershell_ise.exe
selection4:
OriginalFileName: PowerShell.EXE
selection5:
OriginalFileName: powershell_ise.EXE
condition: selection1 and selection2 and selection3 and selection4 and selection5
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited, but if any are present,
filter as needed.
references:
- https://redcanary.com/threat-detection-report/techniques/powershell/
- https://attack.mitre.org/techniques/T1566/001/
tags:
analytic_story:
- Spearphishing Attachments
asset_type: Endpoint
confidence: 100
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
mitre_attack_id:
- T1003.002
- T1003
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 80
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog