71 строка
2.3 KiB
YAML
71 строка
2.3 KiB
YAML
id: c1faf5e8-6958-11ec-90d6-0242ac120003
|
|
name: Fake computer account created
|
|
description: |
|
|
'This query detects domain user accounts creation (event ID 4720) where the username ends with $.
|
|
Accounts that end with $ are normally domain computer accounts and when they are created the event ID 4741 is generated instead.
|
|
Ref: https://blog.menasec.net/2019/02/threat-hunting-6-hiding-in-plain-sights.html'
|
|
severity: Medium
|
|
requiredDataConnectors:
|
|
- connectorId: SecurityEvents
|
|
dataTypes:
|
|
- SecurityEvent
|
|
queryFrequency: 1h
|
|
queryPeriod: 1h
|
|
triggerOperator: gt
|
|
triggerThreshold: 0
|
|
tactics:
|
|
- DefenseEvasion
|
|
relevantTechniques:
|
|
- T1564
|
|
query: |
|
|
SecurityEvent
|
|
| where EventID == 4720 and TargetUserName endswith "$"
|
|
| summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated) by Computer, SubjectUserName, SubjectDomainName, SubjectAccount, SubjectUserSid, SubjectLogonId,
|
|
TargetUserName, TargetDomainName, TargetAccount, TargetSid, UserPrincipalName
|
|
| extend HostName = tostring(split(Computer, ".")[0]), DomainIndex = toint(indexof(Computer, '.'))
|
|
| extend HostNameDomain = iff(DomainIndex != -1, substring(Computer, DomainIndex + 1), Computer)
|
|
| project-away DomainIndex
|
|
entityMappings:
|
|
- entityType: Account
|
|
fieldMappings:
|
|
- identifier: FullName
|
|
columnName: SubjectAccount
|
|
- identifier: Name
|
|
columnName: SubjectUserName
|
|
- identifier: NTDomain
|
|
columnName: SubjectDomainName
|
|
- entityType: Account
|
|
fieldMappings:
|
|
- identifier: Sid
|
|
columnName: SubjectUserSid
|
|
- entityType: Account
|
|
fieldMappings:
|
|
- identifier: FullName
|
|
columnName: TargetAccount
|
|
- identifier: Name
|
|
columnName: TargetUserName
|
|
- identifier: NTDomain
|
|
columnName: TargetDomainName
|
|
- entityType: Account
|
|
fieldMappings:
|
|
- identifier: Sid
|
|
columnName: TargetSid
|
|
- entityType: Host
|
|
fieldMappings:
|
|
- identifier: FullName
|
|
columnName: Computer
|
|
- identifier: HostName
|
|
columnName: HostName
|
|
- identifier: DnsDomain
|
|
columnName: HostNameDomain
|
|
version: 1.0.3
|
|
kind: Scheduled
|
|
metadata:
|
|
source:
|
|
kind: Community
|
|
author:
|
|
name: Vasileios Paschalidis
|
|
support:
|
|
tier: Community
|
|
categories:
|
|
domains: [ "Security - Others" ] |