Files
splunk-security_content/dev/endpoint/excel_spawning_windows_script_host.yml
T
2023-01-20 13:24:15 +01:00

76 lines
2.7 KiB
YAML

name: Excel Spawning Windows Script Host
id: 57fe880a-9be3-11eb-9bf3-acde48001122
version: 1
date: '2021-04-12'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following detection identifies Microsoft Excel spawning Windows Script
Host - `cscript.exe` or `wscript.exe`. Typically, this is not common behavior and
not default with Excel.exe. Excel.exe will generally be found in the following path
`C:\Program Files\Microsoft Office\root\Office16` (version will vary). `cscript.exe`
or `wscript.exe` default location is `c:\windows\system32\` or c:windows\syswow64`.
`cscript.exe` or `wscript.exe` spawning from Excel.exe is common for a spearphishing
attachment and is actively used. Albeit, the command-line executed will most likely
be obfuscated and captured via another detection. During triage, review parallel
processes and identify any files that may have been written. Review the reputation
of the remote destination and block accordingly.
data_source:
- Sysmon Event ID 1
search:
selection1:
Image|endswith:
- cscript.exe
- wscript.exe
ParentImage: excel.exe
condition: selection1
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node.
known_false_positives: False positives should be limited, but if any are present,
filter as needed. In some instances, `cscript.exe` is used for legitimate business
practices.
references:
- https://app.any.run/tasks/8ecfbc29-03d0-421c-a5bf-3905d29192a2/
- https://attack.mitre.org/techniques/T1566/001/
tags:
analytic_story:
- Spearphishing Attachments
asset_type: Endpoint
confidence: 100
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$ by user $user$, indicating potential suspicious macro execution.
mitre_attack_id:
- T1003.002
- T1003
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 80
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566.001/macro/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog