mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
81 lines
3.7 KiB
YAML
81 lines
3.7 KiB
YAML
name: Windows Unsigned DLL Side-Loading
|
|
id: 5a83ce44-8e0f-4786-a775-8249a525c879
|
|
version: 11
|
|
date: '2025-05-02'
|
|
author: Teoderick Contreras, Splunk
|
|
status: production
|
|
type: Anomaly
|
|
data_source:
|
|
- Sysmon EventID 7
|
|
description:
|
|
The following analytic detects the creation of potentially malicious
|
|
unsigned DLLs in the c:\windows\system32 or c:\windows\syswow64 folders. It leverages
|
|
Sysmon EventCode 7 logs to identify unsigned DLLs with unavailable signatures loaded
|
|
in these critical directories. This activity is significant as it may indicate a
|
|
DLL hijacking attempt, a technique used by attackers to gain unauthorized access
|
|
and execute malicious code. If confirmed malicious, this could lead to privilege
|
|
escalation, allowing the attacker to gain elevated privileges and further compromise
|
|
the target system.
|
|
search:
|
|
'`sysmon` EventCode=7 Signed=false OriginalFileName = "-" SignatureStatus="unavailable"
|
|
ImageLoaded IN ("*:\\windows\\system32\\*", "*:\\windows\\syswow64\\*") | fillnull
|
|
| stats count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded
|
|
dest loaded_file loaded_file_path original_file_name process_exec process_guid process_hash
|
|
process_id process_name process_path service_dll_signature_exists service_dll_signature_verified
|
|
signature signature_id user_id vendor_product | `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)` | `windows_unsigned_dll_side_loading_filter`'
|
|
how_to_implement:
|
|
To successfully implement this search, you need to be ingesting
|
|
logs with the process name and imageloaded executions from your endpoints. If you
|
|
are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
|
known_false_positives:
|
|
It is possible some Administrative utilities will load dismcore.dll
|
|
outside of normal system paths, filter as needed.
|
|
references:
|
|
- https://asec.ahnlab.com/en/17692/
|
|
- https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/warzone#:~:text=Warzone%20RAT%20(AKA%20Ave%20Maria)%20is%20a%20remote%20access%20trojan,is%20as%20an%20information%20stealer.
|
|
drilldown_searches:
|
|
- name: View the detection results for - "$dest$"
|
|
search: '%original_detection_search% | search dest = "$dest$"'
|
|
earliest_offset: $info_min_time$
|
|
latest_offset: $info_max_time$
|
|
- name: View risk events for the last 7 days for - "$dest$"
|
|
search:
|
|
'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$")
|
|
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
|
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
|
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
|
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`'
|
|
earliest_offset: $info_min_time$
|
|
latest_offset: $info_max_time$
|
|
rba:
|
|
message: An unsigned dll module was loaded on $dest$
|
|
risk_objects:
|
|
- field: dest
|
|
type: system
|
|
score: 49
|
|
threat_objects: []
|
|
tags:
|
|
analytic_story:
|
|
- China-Nexus Threat Activity
|
|
- Derusbi
|
|
- Warzone RAT
|
|
- Salt Typhoon
|
|
- NjRAT
|
|
- Earth Alux
|
|
asset_type: Endpoint
|
|
mitre_attack_id:
|
|
- T1574.001
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/warzone_rat/unsigned_dll_loaded/loaded_unsigned_dll.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: XmlWinEventLog
|