diff --git a/contentctl.yml b/contentctl.yml index 5cea12db12..41700c7b2b 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -225,4 +225,12 @@ apps: description: The Splunk Add-on for AppDynamics enables you to easily configure data inputs to pull data from AppDynamics' REST APIs hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_314.tgz +- uid: 4221 + title: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk + appid: TA-Cisco-NVM + version: 4.0.7 + description: The Cisco Endpoint Security Analytics (CESA) Add-On for Splunk allows IT administrators to analyze and correlate user and endpoint behavior in Splunk Enterprise. + This Add-on provides configuration and collection of data from the Cisco AnyConnect Network Visibility Module IPFIX (nvzFlow) Collector. + This module collects additional context such as user, device, application, location and destination for flows both on and off premise. + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-endpoint-security-analytics-cesa-add-on-for-splunk_407.tgz githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd diff --git a/data_sources/cisco_network_visibility_module_flow_data.yml b/data_sources/cisco_network_visibility_module_flow_data.yml new file mode 100644 index 0000000000..912d292de3 --- /dev/null +++ b/data_sources/cisco_network_visibility_module_flow_data.yml @@ -0,0 +1,149 @@ +name: Cisco Network Visibility Module Flow Data +id: d49bcd3c-da06-41c6-b33e-8b8d23078f68 +version: 1 +date: '2025-06-30' +author: Nasreddine Bencherchali, Splunk +description: Data source object for Netflow events from Cisco Network Visibility Module +source: not_applicable +sourcetype: cisco:nvm:flowdata +supported_TA: +- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk + url: https://splunkbase.splunk.com/app/4221 + version: 4.0.7 +fields: +- action +- aditional_logged_in_user_list +- aliul +- bytes +- bytes_in +- bytes_out +- da +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- deserialize +- dest +- dest_hostname +- dest_ip +- dest_ipv6 +- dest_port +- dh +- direction +- dp +- dps +- ds +- eventtype +- fd +- fems +- fes +- fet +- field +- flow_dns_suffix +- flow_end_msec +- flow_end_sec +- flow_end_time +- flow_report_stage +- flow_start_msec +- flow_start_sec +- flow_start_time +- flow_version +- fsg +- fsms +- fss +- fst +- fv +- hh +- hm +- host +- ht +- http_host +- http_method +- ibc +- iid +- index +- linecount +- liuat +- liuid +- liuida +- liuidp +- logged_in_user +- logged_in_user_account_type +- logged_in_user_authority +- logged_in_user_principal +- mhl +- mnl +- module_hash_list +- module_name_list +- obc +- pa +- paa +- pap +- parent_process +- parent_process_account +- parent_process_arguments +- parent_process_hash +- parent_process_id +- parent_process_integrity_level +- parent_process_name +- parent_process_path +- parent_process_user_account_type +- parg +- ph +- pid +- pil +- pn +- ppa +- pparg +- ppath +- pph +- ppid +- ppil +- ppn +- pppath +- ppuat +- pr +- process +- process_account_authority +- process_account_principal +- process_arguments +- process_guid +- process_hash +- process_id +- process_integrity_level +- process_name +- process_path +- process_user_account_type +- protocol_identifier +- puat +- puid +- punct +- sa +- source +- sourcetype +- sp +- splunk_server +- splunk_server_group +- sps +- src +- src_interface +- src_ip +- src_ipv6 +- src_port +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestamp +- timestartpos +- transport +- udid +- uri_path +- user +output_fields: +- dest +example_log: 'Jun 26 16:09:18 127.0.0.1 Jun 26 16:09:18 ip-172-31-30-201 fv="nvzFlow_v9" pr="6" sa="172.16.3.110" sp="5203" da="140.82.112.3" dp="443" fd="1" fss="1750954134" fst="Thu Jun 26 16:08:54 2025" fes="1750954134" fet="Thu Jun 26 16:08:54 2025" hh="''" hm="''" ht="''" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" liuid="EC2AMAZ-E56LIG5\Administrator" liuida="EC2AMAZ-E56LIG5" liuidp="Administrator" liuat="2" pa="EC2AMAZ-E56LIG5\Administrator" paa="EC2AMAZ-E56LIG5" pap="Administrator" puat="8194" pn="msiexec.exe" ph="23EC37A4DF21893A1B3B6F5F72B2D78918E86C3A90F9664F8248A2C8219F889A" ppa="EC2AMAZ-E56LIG5\Administrator" ppuat="8194" ppn="cmd.exe" pph="41871DADE953D9F40F4AA445FC19982AB59D263C8AA93D7F67A1451663A09A57" ibc="0" obc="0" ds="us-east-2.compute.internal" dh="github.com" iid="4" mnl="''" mhl="''" fsms="1750954134331" fems="1750954134340" pid="8496" ppath="C:\Windows\system32\msiexec.exe" parg=" /i \"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1218.007/src/T1218.007_JScript.msi\"" ppid="9232" pppath="C:\Windows\system32\cmd.exe" aliul="''" pil="12288" ppil="12288" fsg="1" puid="071161F29663831BB4A1C0FADA9805E0"' diff --git a/data_sources/cisco_network_visibility_module_osquery.yml b/data_sources/cisco_network_visibility_module_osquery.yml new file mode 100644 index 0000000000..8bc2be6846 --- /dev/null +++ b/data_sources/cisco_network_visibility_module_osquery.yml @@ -0,0 +1,51 @@ +name: Cisco Network Visibility Module OSquery +id: d59bcd3c-da06-41c6-b33e-8b8d23078f68 +version: 1 +date: '2025-06-30' +author: Nasreddine Bencherchali, Splunk +description: Data source object for OSquery events from Cisco Network Visibility Module +source: not_applicable +sourcetype: cisco:nvm:osquery +supported_TA: +- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk + url: https://splunkbase.splunk.com/app/4221 + version: 4.0.7 +fields: +- current_page +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- eventtype +- fv +- host +- index +- linecount +- osquery_version +- punct +- qid +- qjr +- qpi +- qpn +- qt +- query_id +- query_json_response +- query_timestamp +- qv +- source +- sourcetype +- splunk_server +- splunk_server_group +- tag +- tag::eventtype +- timeendpos +- timestartpos +- total_pages +- udid +output_fields: +- query_json_response +example_log: 'Jun 30 09:20:43 127.0.0.1 Jun 30 09:20:43 ip-172-31-30-201 fv="nvzFlow_v8" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" qv="5.5.1-dirty" qid="38654705666" qt="1751275242" qpi="1" qpn="1" qjr="[{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"addons-search-detection@mozilla.com\",\"location\":\"app-builtin\",\"name\":\"Add-ons Search Detection\",\"native\":\"\",\"path\":\"null\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.0.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Mozilla \",\"description\":\"Take clips and screenshots from the Web and save them temporarily or permanently.\",\"disabled\":\"1\",\"identifier\":\"screenshots@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Firefox Screenshots\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\screenshots@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"39.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"formautofill@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Form Autofill\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\formautofill@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Fixes for web compatibility with Picture-in-Picture\",\"disabled\":\"0\",\"identifier\":\"pictureinpicture@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Picture-In-Picture\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\pictureinpicture@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.0\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Urgent post-release fixes for web compatibility.\",\"disabled\":\"0\",\"identifier\":\"webcompat@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Web Compatibility Interventions\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"137.7.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Thomas Wisniewski \",\"description\":\"Report site compatibility issues on webcompat.com\",\"disabled\":\"1\",\"identifier\":\"webcompat-reporter@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"WebCompat Reporter\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat-reporter@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.1.0\",\"visible\":\"1\"}]"' diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/deprecated/any_powershell_downloadfile.yml similarity index 98% rename from detections/endpoint/any_powershell_downloadfile.yml rename to detections/deprecated/any_powershell_downloadfile.yml index 0696a658c8..20d9e8c712 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/deprecated/any_powershell_downloadfile.yml @@ -1,9 +1,9 @@ name: Any Powershell DownloadFile id: 1a93b7ea-7af7-11eb-adb5-acde48001122 -version: '15' -date: '2025-05-06' +version: '16' +date: '2025-06-23' author: Michael Haag, Splunk -status: production +status: deprecated type: TTP description: The following analytic detects the use of PowerShell's `DownloadFile` method to download files. It leverages data from Endpoint Detection and Response diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/deprecated/any_powershell_downloadstring.yml similarity index 98% rename from detections/endpoint/any_powershell_downloadstring.yml rename to detections/deprecated/any_powershell_downloadstring.yml index 48464928ef..d477fd6d7e 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/deprecated/any_powershell_downloadstring.yml @@ -1,9 +1,9 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: '12' -date: '2025-05-06' +version: '13' +date: '2025-06-23' author: Michael Haag, Splunk -status: production +status: deprecated type: TTP description: The following analytic detects the use of PowerShell's `DownloadString` method to download files. It leverages data from Endpoint Detection and Response diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/deprecated/windows_installutil_uninstall_option_with_network.yml similarity index 99% rename from detections/endpoint/windows_installutil_uninstall_option_with_network.yml rename to detections/deprecated/windows_installutil_uninstall_option_with_network.yml index f65912f4fa..de81a547e1 100644 --- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml +++ b/detections/deprecated/windows_installutil_uninstall_option_with_network.yml @@ -1,9 +1,9 @@ name: Windows InstallUtil Uninstall Option with Network id: 1a52c836-43ef-11ec-a36c-acde48001122 -version: 12 -date: '2025-05-02' +version: 13 +date: '2025-06-26' author: Michael Haag, Splunk -status: production +status: deprecated type: TTP description: The following analytic identifies the use of Windows InstallUtil.exe making a remote network connection using the `/u` (uninstall) switch. This detection diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index d236d55423..0de2a89b07 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,7 +1,7 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 version: 12 -date: '2025-07-03' +date: '2025-07-07' author: Bhavin Patel, Splunk, sventec, Github Community status: production type: TTP @@ -17,6 +17,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes where @@ -77,6 +78,7 @@ tags: - CISA AA22-264A - Compromised Windows Host - PHP-CGI RCE Attack on Japanese Organizations + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1003 @@ -88,8 +90,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index cc606ede9b..e4c528392f 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -1,7 +1,7 @@ name: BITSAdmin Download File id: 80630ff4-8e4c-11eb-aab5-acde48001122 -version: 10 -date: '2025-05-02' +version: 11 +date: '2025-06-24' author: Michael Haag, Sittikorn S status: production type: TTP @@ -90,12 +90,12 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog -- name: True Positive Test +- name: True Positive Test - CrowdStrike attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log source: crowdstrike diff --git a/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml new file mode 100644 index 0000000000..4a4cc8fbb8 --- /dev/null +++ b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml @@ -0,0 +1,97 @@ +name: Cisco NVM - Curl Execution With Insecure Flags +id: cc695238-3117-4e60-aa83-4beac2a42c69 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects the use of `curl.exe` with insecure flags such as `-k`, `--insecure`, `--proxy-insecure`, or `--doh-insecure` + which disable TLS certificate validation. + It leverages Cisco Network Visibility Module (NVM) flow data and process arguments + to identify outbound connections initiated by curl where TLS checks were explicitly disabled. + This behavior may indicate an attempt to bypass certificate validation to connect to potentially untrusted or malicious endpoints, + a common tactic in red team operations, malware staging, or data exfiltration over HTTPS. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "curl.exe" + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | regex process_arguments="(?i)(?[^\s\"']+)$" + | lookup typo_squatted_python_packages + typosquatted_package_name as package_name + OUTPUTNEW comment package_official_url + | where isnotnull(comment) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___installation_of_typosquatted_python_package_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + In addition to this, the search make use of the lookup "typo_squatted_python_packages". Which needs to be configured and tuned. +known_false_positives: | + False positives should be very minimal to non existent, as the names of the packages in the lookup are all extracted from previously malicious packages. +references: + - https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218/ + - https://blog.checkpoint.com/securing-the-cloud/pypi-inundated-by-malicious-typosquatting-campaign/ + - https://rhisac.org/threat-intelligence/typosquatting-campaign-targets-python-developers-with-hundreds-of-malicious-libraries/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Host $src$ used pip or poetry to install a likely typosquatted python package "$package_name$" from $dest_hostname$ + risk_objects: + - field: src + type: system + score: 60 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1059 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml new file mode 100644 index 0000000000..f31fced3ad --- /dev/null +++ b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml @@ -0,0 +1,103 @@ +name: Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI +id: f2a9df84-9b01-4a21-9e3a-7aa1a217f69e +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects suspicious use of 'mshta.exe' or 'rundll32.exe' invoking 'mshtml.dll' + or the 'RunHTMLApplication' export without including a direct HTTP/HTTPS URL in the command line. + This pattern could be associated with obfuscated script execution used by threat actors during + initial access or payload staging. The absence of a visible URL may indicate attempts to evade static + detections by embedding the URL via string concatenation, encoding (e.g., hex), or indirect script loaders + like 'GetObject()'. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + ( + ( + process_name = "mshta.exe" + process_arguments IN ("*javascript*", "*vbscript*") + ) + OR + ( process_name = "rundll32.exe" AND + process_arguments = "*mshtml*" AND + process_arguments = "*RunHTMLApplication*" + ) + ) + NOT process_arguments IN ("*http://*", "*https://*") + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + False positives should be minimal as the presence of a network connection during such executions increases the likelihood of malicious behavior. +references: + - https://attack.mitre.org/techniques/T1218/005/ + - https://redcanary.com/blog/mshta-attack-technique/ + - https://lolbas-project.github.io/lolbas/Binaries/Rundll32/ + - https://learn.microsoft.com/en-us/windows/win32/api/mshtml/nf-mshtml-mshtml_runhtmlapplication +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ executed $process_name$ with potential obfuscated logic and initiated a network connection to $dest_hostname$ / $dest$ over $dest_port$. + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1218.005 + - T1059.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml new file mode 100644 index 0000000000..60f9abcc4e --- /dev/null +++ b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml @@ -0,0 +1,99 @@ +name: Cisco NVM - Non-Network Binary Making Network Connection +id: c6db35af-8a0e-4b61-88ed-738e66f15715 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects network connections initiated by binaries that are not typically associated with network communication, + such as 'notepad.exe', 'calc.exe' or 'write.exe'. + It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path, and parent process information. + These applications are normally used for locally and do not require outbound network access. When they do initiate such connections, it may indicate process hollowing, code injection, or proxy execution, where adversaries abuse a trusted process to mask malicious activity. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name IN ( + "notepad.exe", "write.exe", "mspaint.exe", "calc.exe", + "addinutil.exe", "cmstp.exe", "dialer.exe", "eqnedt32.exe", "IMEWDBLD.exe" + ) + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___non_network_binary_making_network_connection_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Rare cases may exist where these binaries are used by plugins or third-party extensions to initiate outbound communication. + However, such behavior is extremely uncommon and should be investigated for potential injection or abuse. +references: + - https://redcanary.com/threat-detection-report/techniques/process-injection/ + - https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ observed $process_path$ initiating a network connection to $dest$ over port $dest_port$, which is highly unusual + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1055 + - T1036 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata \ No newline at end of file diff --git a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml new file mode 100644 index 0000000000..0f8d7d9550 --- /dev/null +++ b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml @@ -0,0 +1,96 @@ +name: Cisco NVM - Outbound Connection to Suspicious Port +id: fc32a8d5-bc79-4437-b48f-4646ab7bed9d +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + The following analytic detects any outbound network connection from an endpoint process to a known suspicious or non-standard port. + It leverages Cisco Network Visibility Module flow data logs to identify potentially suspicious behavior by looking at processes + communicating over ports like 4444, 2222, or 51820 are commonly used by tools like Metasploit, SliverC2 or other pentest, red team or malware. + These connections are worth investigating further, especially when initiated by unexpected or non-network-native binaries. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | lookup suspicious_ports_list dest_port OUTPUTNEW comment as dest_port_metadata confidence as dest_confidence category as dest_port_category + | where isnotnull(dest_port_metadata) + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___outbound_connection_to_suspicious_port_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some legitimate applications may use high or non-standard ports, such as alternate SSH daemons or development tools. + However, many of these ports are commonly used by threat actors for reverse shells or C2 communications. + Review the associated process and command-line context to determine intent. +references: + - https://mthcht.medium.com/hunting-for-suspicious-ports-activities-50ef56d5cef +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ established an outbound network connection via the process $process_path$ with the commandline arguments $process_arguments$ to $dest$ over suspicious port $dest_port$. + risk_objects: + - field: dest + type: system + score: 30 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1571 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml new file mode 100644 index 0000000000..825b83b0de --- /dev/null +++ b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml @@ -0,0 +1,106 @@ +name: Cisco NVM - Rclone Execution With Network Activity +id: 719f8c78-b20d-4bb9-8c33-6d1a762e7a9a +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This detection identifies execution of the file synchronization utility "rclone". + It leverages Cisco Network Visibility Module logs, specifically flow data in order to capture process executions + initiating network connections. + While rclone is a legitimate command-line tool for syncing data to cloud storage providers, it has been widely abused by threat actors for data exfiltration. + This analytic inspects process name and arguments for rclone and flags usage of suspicious flags. + If matched, this could indicate malicious usage for stealthy data exfiltration or cloud abuse. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + ( + process_name = "rclone.exe" + OR + ( + process_arguments = "* copy *" + process_arguments = "*\\\\*" + process_arguments IN ("*remote:*", "*mega:*", "*ftp:*", "*ftp1:*") + ) + OR + ( + process_arguments IN ("*remote:*", "*mega:*", "*ftp:*", "*ftp1:*") + process_arguments = "*--transfers" + process_arguments = "*--ignore-existing*" + process_arguments = "*--auto-confirm*" + ) + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___rclone_execution_with_network_activity_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Rclone is used legitimately in some backup or other workflows. Tune this rule based on known-good operational usage or restrict by known user/service accounts an specific folders or remote names. +references: + - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ + - https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/ + - https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ + - https://redcanary.com/blog/threat-detection/rclone-mega-extortion/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Rclone was executed on $src$ using flags $process_arguments$ and connected to $dest_hostname$ over $dest_port$. + risk_objects: + - field: src + type: system + score: 60 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1567.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml new file mode 100644 index 0000000000..ff83eb50e0 --- /dev/null +++ b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml @@ -0,0 +1,94 @@ +name: Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download +id: 18f0d27d-569e-4bc4-96e1-09b214fa73c0 +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects suspicious use of `rundll32.exe` in combination with `mshtml.dll` and the export `RunHTMLApplication`. + This behavior is often observed in malware to execute JavaScript or VBScript in memory, enabling payload staging or + bypassing script execution policies and bypassing the usage of the "mshta.exe" binary. + The detection leverages Cisco Network Visibility Module telemetry which offers network flow activity + along with process information such as command-line arguments + If confirmed malicious, this activity may indicate initial access or payload download. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "rundll32.exe" + process_arguments = "*mshtml*" + process_arguments IN ("*135*", "*RunHTMLApplication*") + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + `rundll32.exe` using `mshtml.dll` is rare in legitimate environments. However, edge cases might exist. Tuning may be needed in environments with custom automation scripts. +references: + - https://lolbas-project.github.io/lolbas/Binaries/Rundll32/ + - https://redcanary.com/blog/threat-detection/threat-research-questions/ + - https://twitter.com/n1nj4sec/status/1421190238081277959 + - https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt + - http://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_DETECTION_BYPASS.txt +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: $process_path$ was executed on $src$ leveraging the mshtml.dll and the RunHTMLApplication export to download a potentially suspicious file from $dest_hostname$. + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1218.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml new file mode 100644 index 0000000000..120f8e623e --- /dev/null +++ b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml @@ -0,0 +1,94 @@ +name: Cisco NVM - Susp Script From Archive Triggering Network Activity +id: 8b07c2c9-0cde-4c44-9fa6-59dcf2b25777 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects script execution (`wscript.exe` or `cscript.exe`) triggered from compressed files opened directly using + `explorer.exe`, `winrar.exe`, or `7zFM.exe`. + When a user double clicks on a ".js" file from within one of these compressed files. Its extracted temporally in the temp directory in folder with certain markers. + It leverages Cisco Network Visibility Module (NVM) flow data, in order to look for a specific parent/child relationship and an initiated network connection. + This behavior is exploited by threat actors such as Scarlet Goldfinch to deliver and run malicious scripts as an initial access technique. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + parent_process_name IN ("explorer.exe", "winrar.exe", "7zFM.exe") + process_name IN ("wscript.exe", "cscript.exe") + process_arguments = "*\\AppData\\Local\\Temp\\*" + process_arguments IN ("*\\rar*", "*\\7z*", "*.zip*") + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___susp_script_from_archive_triggering_network_activity_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some software installers or automation scripts may extract and run scripts from archive files in temporary directories. + However, it is uncommon for such scripts to initiate outbound network connections immediately upon extraction. + This behavior should be considered suspicious and investigated, especially in environments where such scripting is not typical. +references: + - https://redcanary.com/threat-detection-report/threats/scarlet-goldfinch/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: $process_path$ running from $parent_process_name$ with archive-related execution in Temp was observed from host $src$ + performing network a connection towards $dest$ / $dest_hostname$ over port $dest_port$. + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1059.005 + - T1204.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml new file mode 100644 index 0000000000..7d5739263c --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml @@ -0,0 +1,112 @@ +name: Cisco NVM - Suspicious Download From File Sharing Website +id: 94ebc001-35e7-4ae8-9b0e-52766b2f99c7 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects suspicious downloads from common file sharing and content delivery platforms using known living-off-the-land binaries (LOLBins) + such as 'curl.exe', 'certutil.exe', 'msiexec.exe', 'powershell.exe', 'wmic.exe', and others. + It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path, + and parent process information. These tools are often abused by adversaries and malware to retrieve payloads from public hosting platforms + such as GitHub, Discord CDN, Transfer.sh, or Pastebin. + This detection helps identify potential initial access, payload staging, or command and control activity using legitimate services. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + ( + (process_name = "svchost.exe" process_arguments = "*-s BITS*") + OR + process_name IN ( + "curl.exe", "wmic.exe", "wscript.exe", "cscript.exe", "certutil.exe", + "msiexec.exe", "hh.exe", "powershell.exe", "pwsh.exe", "powershell_ise.exe", + "installutil.exe", "certoc.exe", "bitsadmin.exe" + ) + ) + dest_hostname IN ( + "*.githubusercontent.com*", "*anonfiles.com*", "*cdn.discordapp.com*", "*ddns.net*", + "*dl.dropboxusercontent.com*", "*ghostbin.co*", "*glitch.me*", "*gofile.io*", + "*hastebin.com*", "*mediafire.com*", "*mega.nz*", "*onrender.com*", "*pages.dev*", + "*paste.ee*", "*pastebin.*", "*pastetext.net*", "*privatlab.*", + "*send.exploit.in*", "*sendspace.com*", "*storage.googleapis.com*", + "*storjshare.io*", "*supabase.co*", "*temp.sh*", "*transfer.sh*", "*trycloudflare.com*", + "*ufile.io*", "*w3spaces.com*", "*workers.dev*" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_download_from_file_sharing_website_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some system administrators or development teams may use tools like curl or PowerShell to download files from public services + for legitimate automation or scripting purposes. However, use of these binaries to contact domains commonly associated with file sharing or temporary hosting + should be carefully reviewed, as such services are frequently abused by threat actors for malware delivery and staging. + Tuning by domain allowlisting or internal usage policies is recommended. +references: + - https://twitter.com/jhencinski/status/1102695118455349248 + - https://isc.sans.edu/forums/diary/Investigating+Microsoft+BITS+Activity/23281/ + - https://www.virustotal.com/gui/domain/paste.ee/relations + - https://www.cisa.gov/uscert/ncas/alerts/aa22-321a + - https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ used $process_path$ to download content from the file-sharing domain $dest_hostname$ over port $dest_port$ + risk_objects: + - field: src + type: system + score: 30 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1197 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml new file mode 100644 index 0000000000..91444e9e9a --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml @@ -0,0 +1,132 @@ +name: Cisco NVM - Suspicious File Download via Headless Browser +id: cd0e816f-f67d-4dbe-a153-480b546e867e +version: 1 +date: '2025-07-02' +author: Nasreddine Bencherchali, Splunk +status: production +type: TTP +description: | + This analytic identifies the use of Chromium-based browsers (like Microsoft Edge) running in headless mode with the `--dump-dom` argument. + This behavior has been observed in attack campaigns such as DUCKTAIL, where browsers are automated to stealthily download content from the internet using direct URLs or suspicious hosting platforms. + The detection focuses on identifying connections to known file-sharing domains or direct IPs extracted from command-line arguments and cross-checks those against the destination of the flow. + Since it leverages Cisco Network Visibility Module telemetry, the rule triggers only if a network connection is made. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + + ``` Usually the initiator of the connection is the child process, meaning the parent will contain the suspicious command.``` + + ( + parent_process_name IN ("brave.exe", "chrome.exe", "msedge.exe", "opera.exe", "vivaldi.exe") + OR + process_name IN ("brave.exe", "chrome.exe", "msedge.exe", "opera.exe", "vivaldi.exe") + ) + ( + (parent_process_arguments="*--headless*" parent_process_arguments="*--dump-dom*") + OR + (process_arguments="*--headless*" process_arguments="*--dump-dom*") + ) + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + + ``` In order to avoid matching with any public IP, we extract the IP value from the CommandLine and filter on it``` + + | rex field=parent_process_arguments "(?i)\\b(?:https?|ftp)://(?(?:\\d{1,3}\\.){3}\\d{1,3})" + | rex field=process_arguments "(?i)\\b(?:https?|ftp)://(?(?:\\d{1,3}\\.){3}\\d{1,3})" + | eval direct_ip_match=if(dest == extracted_ip_child, 1, if(dest == extracted_ip_parent, 1, 0)) + + | where ( + dest_hostname IN ( + "*.githubusercontent.com*", "*anonfiles.com*", "*cdn.discordapp.com*", "*ddns.net*", + "*dl.dropboxusercontent.com*", "*ghostbin.co*", "*glitch.me*", "*gofile.io*", + "*hastebin.com*", "*mediafire.com*", "*mega.nz*", "*onrender.com*", "*pages.dev*", + "*paste.ee*", "*pastebin.*", "*pastetext.net*", "*privatlab.*", + "*send.exploit.in*", "*sendspace.com*", "*storage.googleapis.com*", + "*storjshare.io*", "*supabase.co*", "*temp.sh*", "*transfer.sh*", "*trycloudflare.com*", + "*ufile.io*", "*w3spaces.com*", "*workers.dev*" + ) + OR direct_ip_match = 1 + ) + + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_file_download_via_headless_browser_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some internal automation frameworks may invoke Chromium browsers in headless mode to programmatically access internal services or webpages. + These tools may occasionally download legitimate resources as part of their normal behavior. + Tuning based on command-line patterns or known dest hostnames may be required to avoid noise. +references: + - https://labs.withsecure.com/content/dam/labs/docs/WithSecure_Research_DUCKTAIL.pdf + - https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html + - https://x.com/mrd0x/status/1478234484881436672?s=12 + - https://developer.chrome.com/docs/chromium/headless +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious file download using the Chromium-based browser "$parent_process_name$" via the commandline $process_arguments$. + Observed on host $src$ communicating with $dest$ / $dest_hostname$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1105 + - T1059 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml new file mode 100644 index 0000000000..48b1e2beda --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml @@ -0,0 +1,103 @@ +name: Cisco NVM - Suspicious Network Connection From Process With No Args +id: 54fa06c5-96a2-4406-a4a7-44d93ddbd173 +version: 1 +date: '2025-07-02' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects system binaries that are commonly abused in process injection techniques but are observed without any command-line arguments. + It leverages Cisco Network Visibility Module (NVM) flow data and process arguments + to identify outbound connections initiated by curl where TLS checks were explicitly disabled. + Binaries such as `rundll32.exe`, `regsvr32.exe`, `dllhost.exe`, `svchost.exe`, and others are legitimate Windows processes that are often injected into by malware or post-exploitation frameworks (e.g., Cobalt Strike) to hide execution. + When these processes are seen initiating a network connection with an empty or missing command line, it can indicate + potential injection and communication with a command and control server. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name IN ( + "backgroundtaskhost.exe", "svchost.exe", "dllhost.exe", "werfault.exe", + "searchprotocolhost.exe", "wuauclt.exe", "spoolsv.exe", "rundll32.exe", + "regasm.exe", "regsvr32.exe", "regsvcs.exe" + ) + NOT process_arguments="*" + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_network_connection_from_process_with_no_args_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some system binaries may execute without arguments in rare legitimate scenarios (e.g., certain service launches), and initiate + a network connection to microsoft servers for telemetry or update purposes. Apply additional filters as needed. + However, binaries such as `rundll32.exe` or `dllhost.exe` running with no command-line context are highly suspicious and warrant investigation. +references: + - https://redcanary.com/threat-detection-report/techniques/process-injection/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The $process_name$ was seen on host $src$ executing without any command-line arguments and initiating a network connection towards $dest$. This might indicate a potential communication with a C&C server. + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1055 + - T1218 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata \ No newline at end of file diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml new file mode 100644 index 0000000000..fd4adcad89 --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml @@ -0,0 +1,96 @@ +name: Cisco NVM - Suspicious Network Connection Initiated via MsXsl +id: 1cbcf75f-0e45-4f29-8c1b-7fcd7e55cc55 +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic identifies the use of `msxsl.exe` initiating a network connection to a non-private IP address. + Although `msxsl.exe` is a legitimate Microsoft utility used to apply XSLT transformations, adversaries can abuse it + to execute arbitrary code or load external resources in an evasive manner. + This detection leverages Cisco NVM telemetry to identify potentially malicious use of `msxsl.exe` making network connections + that may indicate command and control (C2) or data exfiltration activity. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "msxsl.exe" + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_network_connection_initiated_via_msxsl_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + False positives may occur in development or administrative environments where msxsl.exe is used + for legitimate XML transformations. However, its use is uncommon in standard user activity + and should be reviewed in most environments. +references: + - https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msxsl/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Host $src$ used msxsl.exe to initiate a suspicious network connection to $dest$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1220 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml new file mode 100644 index 0000000000..f169459f60 --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml @@ -0,0 +1,105 @@ +name: Cisco NVM - Suspicious Network Connection to IP Lookup Service API +id: 568cb83e-d79e-4a23-85ec-6e1f6c30cb2f +version: 1 +date: '2025-07-04' +author: Nasreddine Bencherchali, Splunk, Janantha Marasinghe +status: production +type: Anomaly +description: | + This analytic identifies non-browser processes reaching out to public IP lookup or geolocation services, + such as `ipinfo.io`, `icanhazip.com`, `ip-api.com`, and others. + These domains are commonly used by legitimate tools, but their usage outside of browsers may indicate + network reconnaissance, virtual machine detection, or staging by malware. + This activity is observed in post-exploitation frameworks, stealer malware, and advanced threat actor campaigns. + The detection relies on Cisco Network Visibility Module (NVM) telemetry and excludes known browser + processes to reduce noise. +search: | + `cisco_network_visibility_module_flowdata` + dest_hostname IN ( + "*api.2ip.ua*", "*api.bigdatacloud.net*", "*api.ipify.org*", "*whatismyipaddress.com*", + "*canireachthe.net*", "*checkip.amazonaws.com*", "*checkip.dyndns.org*", "*curlmyip.com*", + "*db-ip.com*", "*edns.ip-api.com*", "*eth0.me*", "*freegeoip.app*", "*geoipy.com*", "*getip.pro*", + "*icanhazip.com*", "*ident.me*", "*ifconfig.io*", "*ifconfig.me*", "*ip-api.com*", "*ip.360.cn*", + "*ip.anysrc.net*", "*ip.taobao.com*", "*ip.tyk.nu*", "*ipaddressworld.com*", "*ipapi.co*", + "*ipconfig.io*", "*ipecho.net*", "*ipinfo.io*", "*ipip.net*", "*iplocation.net*", + "*ipof.in*", "*ipv6-test.com*", "*ipwho.is*", "*trackip.net*", "*inet-ip.info*", + "*jsonip.com*", "*myexternalip.com*", "*seeip.org*", "*wgetip.com*", + "*whatismyip.akamai.com*", "*whois.pconline.com.cn*", "*wtfismyip.com*", "*ip.cn" + ) + NOT process_name IN ( + "brave.exe", "chrome.exe", "firefox.exe", "iexplore.exe", "maxthon.exe", + "MicrosoftEdge.exe", "msedge.exe", "msedgewebview2.exe", "opera.exe", "safari.exe", + "seamonkey.exe", "vivaldi.exe", "whale.exe" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Internal scripts or agents performing network checks may query IP geolocation services. + Tune by excluding known tools or adding internal allowlists for destination domains or process names and commandlines. +references: + - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_domain_external_ip_lookup.yml + - https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ made a network request to IP lookup service $dest_hostname$ using suspicious process $process_path$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1590.005 + - T1016 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml new file mode 100644 index 0000000000..1209802782 --- /dev/null +++ b/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml @@ -0,0 +1,102 @@ +name: Cisco NVM - Webserver Download From File Sharing Website +id: 1984f997-3b49-4d4b-a7e9-dc5dbf88370e +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: TTP +description: | + This analytic detects unexpected outbound network connections initiated by known webserver processes such as `httpd.exe`, `nginx.exe`, or `tomcat.exe` to common file sharing or public content hosting services like GitHub, Discord CDN, Transfer.sh, or Pastebin. + Webservers are rarely expected to perform outbound downloads, especially to dynamic or anonymous file hosting domains. This behavior is often associated with server compromise, + where an attacker uses a reverse shell, webshell, or injected task to fetch malware or tools post-exploitation. + The detection leverages Cisco Network Visibility Module flow data, enriched with process context, to identify this highly suspicious behavior. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name IN ( + "http*.exe", "nginx*.exe", "php*.exe", "php-cgi*.exe", "tomcat*.exe" + ) + dest_hostname IN ( + "*.githubusercontent.com*", "*anonfiles.com*", "*cdn.discordapp.com*", "*ddns.net*", + "*dl.dropboxusercontent.com*", "*ghostbin.co*", "*glitch.me*", "*gofile.io*", + "*hastebin.com*", "*mediafire.com*", "*mega.nz*", "*onrender.com*", "*pages.dev*", + "*paste.ee*", "*pastebin.*", "*pastetext.net*", "*privatlab.*", + "*send.exploit.in*", "*sendspace.com*", "*storage.googleapis.com*", + "*storjshare.io*", "*supabase.co*", "*temp.sh*", "*transfer.sh*", "*trycloudflare.com*", + "*ufile.io*", "*w3spaces.com*", "*workers.dev*" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_name process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___webserver_download_from_file_sharing_website_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + In rare cases, a web server may make outbound connections to pull content for legitimate purposes (e.g., downloading templates or updates from a trusted source). + However, communication to anonymous file-sharing or temporary content domains is strongly suspicious. + If legitimate use is confirmed, domain- or process-level allowlisting is recommended. +references: + - https://www.cisa.gov/news-events/alerts/2023/04/13/cisa-adds-3-known-exploited-vulnerabilities-kev-catalog + - https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/ + - https://research.splunk.com/endpoint/4e8391eb-527e-4e39-9a17-c5bde2f89158/ +rba: + message: The host $src$ ran web server process $process_path$ which downloaded content from $dest_hostname$ over port $dest_port$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_name + type: process_name +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1105 + - T1190 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 49584331fd..6b8d49e5ff 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect HTML Help URL in Command Line id: 8c5835b9-39d9-438b-817c-95f14c69a31e -version: 11 -date: '2025-05-02' +version: 12 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP @@ -16,6 +16,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process=*http* by Processes.action Processes.dest Processes.original_file_name Processes.parent_process @@ -78,6 +79,7 @@ tags: - Suspicious Compiled HTML Activity - Living Off The Land - Compromised Windows Host + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.001 @@ -87,8 +89,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 8699348b29..a5e586d3da 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect MSHTA Url in Command Line id: 9b3af1e6-5b68-11eb-ae93-0242ac130002 -version: 13 -date: '2025-05-19' +version: 14 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP @@ -16,6 +16,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process="*http://*" @@ -80,6 +81,7 @@ tags: - Living Off The Land - Suspicious MSHTA Activity - XWorm + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.005 @@ -89,8 +91,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 4f97b47f3e..4a4805250a 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,7 +1,7 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 11 -date: '2025-05-02' +version: 12 +date: '2025-07-04' author: Michael Haag, Splunk status: production type: TTP @@ -17,18 +17,28 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_rclone` Processes.process - IN ("*copy*", "*mega*", "*pcloud*", "*ftp*", "*--config*", "*--progress*", "*--no-check-certificate*", - "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", "*--multi-thread-streams*") +- Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_rclone` + Processes.process IN ( + "*copy*", "*mega*", "*pcloud*", "*ftp*", + "*--config*", "*--progress*", "*--no-check-certificate*", + "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", + "*--multi-thread-streams*" + ) by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `detect_rclone_command_line_usage_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `detect_rclone_command_line_usage_filter` +how_to_implement: | + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. @@ -37,27 +47,27 @@ how_to_implement: The detection is based on data that originates from Endpoint D the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: False positives should be limited as this is restricted to - the Rclone process name. Filter or tune the analytic as needed. +known_false_positives: | + False positives should be limited as this is restricted to the Rclone process name. Filter or tune the analytic as needed. references: -- https://redcanary.com/blog/rclone-mega-extortion/ -- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations -- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ -- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ + - https://redcanary.com/blog/rclone-mega-extortion/ + - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations + - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ + - https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ drilldown_searches: -- name: View the detection results for - "$user$" and "$dest$" - search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", - "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) - as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk - Message" values(analyticstories) as "Analytic Stories" values(annotations._all) - as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" - by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ + - name: View the detection results for - "$user$" and "$dest$" + search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$user$" and "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to connect to a remote cloud service @@ -76,21 +86,27 @@ rba: type: process_name tags: analytic_story: - - DarkSide Ransomware - - Ransomware - - Black Basta Ransomware - - Cactus Ransomware + - DarkSide Ransomware + - Ransomware + - Black Basta Ransomware + - Cactus Ransomware + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1020 product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog + - name: True Positive Test - Sysmon + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata \ No newline at end of file diff --git a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml index 4362461f14..c52cb0ddf9 100644 --- a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml @@ -1,41 +1,56 @@ name: DLLHost with no Command Line Arguments with Network id: f1c07594-a141-11eb-8407-acde48001122 -version: 12 -date: '2025-06-10' +version: 13 +date: '2025-06-30' author: Steven Dick, Michael Haag, Splunk status: production type: TTP -description: The following analytic detects instances of DLLHost.exe running without - command line arguments while establishing a network connection. This behavior is - identified using Endpoint Detection and Response (EDR) telemetry, focusing on process - execution and network activity data. It is significant because DLLHost.exe typically - runs with specific arguments, and its absence can indicate malicious activity, such - as Cobalt Strike usage. If confirmed malicious, this activity could allow attackers - to execute code, move laterally, or exfiltrate data, posing a severe threat to the - network's security. +description: | + The following analytic detects instances of DLLHost.exe running without + command line arguments while establishing a network connection. + This behavior is identified using Endpoint Detection and Response (EDR) telemetry, + focusing on process execution and network activity data. + It is significant because DLLHost.exe typically runs with specific arguments, + and its absence can indicate malicious activity, such as Cobalt Strike usage. + If confirmed malicious, this activity could allow attackers to execute code, + move laterally, or exfiltrate data, posing a severe threat to the network's security. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe - Processes.action!="blocked" by host _time span=1h +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime FROM datamodel=Endpoint.Processes where + Processes.process_name=dllhost.exe + Processes.action!="blocked" + by host _time span=1h Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | regex process="(?i)(dllhost\.exe.{0,4}$)" - | rename dest as src | join host process_id [| tstats `security_content_summariesonly` - count latest(All_Traffic.dest) as dest latest(All_Traffic.dest_ip) as dest_ip latest(All_Traffic.dest_port) - as dest_port FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 - by host All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in All_Traffic.bytes_out - All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.dvc All_Traffic.protocol - All_Traffic.protocol_version All_Traffic.src All_Traffic.src_ip All_Traffic.src_port - All_Traffic.transport All_Traffic.user All_Traffic.vendor_product All_Traffic.direction - All_Traffic.process_id - | `drop_dm_object_name(All_Traffic)`] | `dllhost_with_no_command_line_arguments_with_network_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | regex process="(?i)(dllhost\.exe.{0,4}$)" + | rename dest as src + | join host process_id [ + | tstats `security_content_summariesonly` + count + latest(All_Traffic.dest) as dest + latest(All_Traffic.dest_ip) as dest_ip + latest(All_Traffic.dest_port) as dest_port + FROM datamodel=Network_Traffic.All_Traffic where + All_Traffic.dest_port != 0 + by host All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in + All_Traffic.bytes_out All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port + All_Traffic.dvc All_Traffic.protocol All_Traffic.protocol_version All_Traffic.src + All_Traffic.src_ip All_Traffic.src_port All_Traffic.transport All_Traffic.user + All_Traffic.vendor_product All_Traffic.direction All_Traffic.process_id + | `drop_dm_object_name(All_Traffic)` + ] + | `dllhost_with_no_command_line_arguments_with_network_filter` +how_to_implement: | + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. @@ -44,7 +59,8 @@ how_to_implement: The detection is based on data that originates from Endpoint D the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: Although unlikely, some legitimate third party applications +known_false_positives: | + Although unlikely, some legitimate third party applications may use a moved copy of dllhost, triggering a false positive. references: - https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile diff --git a/detections/endpoint/suspicious_curl_network_connection.yml b/detections/endpoint/suspicious_curl_network_connection.yml index 9202695dbc..22c426f43c 100644 --- a/detections/endpoint/suspicious_curl_network_connection.yml +++ b/detections/endpoint/suspicious_curl_network_connection.yml @@ -38,7 +38,6 @@ how_to_implement: The detection is based on data that originates from Endpoint D known_false_positives: Unknown. Filter as needed. references: - https://redcanary.com/blog/clipping-silver-sparrows-wings/ -- https://www.marcosantadev.com/manage-plist-files-plistbuddy/ rba: message: Suspicious usage of curl on $dest$ risk_objects: diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index ed5a43f75b..a0568f993c 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -1,11 +1,12 @@ name: Windows Curl Download to Suspicious Path id: c32f091e-30db-11ec-8738-acde48001122 -version: 13 -date: '2025-05-02' -author: Michael Haag, Splunk +version: 14 +date: '2025-06-30' +author: Michael Haag, Nasreddine Bencherchali, Splunk status: production type: TTP -description: The following analytic detects the use of Windows Curl.exe to download +description: | + The following analytic detects the use of Windows Curl.exe to download a file to a suspicious location, such as AppData, ProgramData, or Public directories. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions that include the -O or --output options. This activity is @@ -17,17 +18,34 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_curl` Processes.process - IN ("*-O *","*--output*") Processes.process IN ("*\\appdata\\*","*\\programdata\\*","*\\public\\*") +- Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_curl` + Processes.process IN ("*-O *","*--output*") + Processes.process IN ( + "*:\\PerfLogs\\*", + "*:\\Windows\\Temp\\*", + "*\\AppData\\*", + "*\\ProgramData\\*", + "*\\Users\\Public\\*", + "*%AppData%*", + "*%Public%*", + "*%Temp%*", + "*%tmp%*" + ) by Processes.action Processes.dest Processes.original_file_name Processes.parent_process - Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id - Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec - Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level - Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_curl_download_to_suspicious_path_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec + Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_curl_download_to_suspicious_path_filter` +how_to_implement: | + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. @@ -36,8 +54,8 @@ how_to_implement: The detection is based on data that originates from Endpoint D the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: It is possible Administrators or super users will use Curl - for legitimate purposes. Filter as needed. +known_false_positives: | + It is possible Administrators or super users will use Curl for legitimate purposes. Filter as needed. references: - https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/ - https://attack.mitre.org/techniques/T1105/ @@ -80,6 +98,7 @@ tags: - Salt Typhoon - Ingress Tool Transfer - IcedID + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1105 @@ -89,8 +108,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 41187a45f9..fc2336e6a9 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -1,7 +1,7 @@ name: Windows Curl Upload to Remote Destination id: 42f8f1a2-4228-11ec-aade-acde48001122 -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-06-20' author: Michael Haag, Splunk status: production type: TTP @@ -16,6 +16,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_curl` Processes.process IN ("*-T *","*--upload-file *", "*-d *", "*--data *", "*-F *") by Processes.action @@ -74,6 +75,7 @@ tags: analytic_story: - Compromised Windows Host - Ingress Tool Transfer + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1105 @@ -83,8 +85,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_file_download_via_certutil.yml b/detections/endpoint/windows_file_download_via_certutil.yml index ae8b5b588f..954837a167 100644 --- a/detections/endpoint/windows_file_download_via_certutil.yml +++ b/detections/endpoint/windows_file_download_via_certutil.yml @@ -1,7 +1,7 @@ name: Windows File Download Via CertUtil id: 7fac8d40-e370-45ea-a4a3-031bbcc18b02 -version: 2 -date: '2025-05-02' +version: 3 +date: '2025-06-30' author: Nasreddine Bencherchali, Michael Haag, Splunk status: production type: TTP @@ -10,6 +10,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` AND ((Processes.process IN ("*-URL *", "*/URL *")) OR (Processes.process IN ("*urlcache*", "*verifyctl*") AND Processes.process IN ("*/f *", "*-f *"))) by Processes.action Processes.dest @@ -79,6 +80,7 @@ tags: - Flax Typhoon - Compromised Windows Host - CISA AA22-277A + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1105 @@ -88,9 +90,14 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_file_download_via_powershell.yml b/detections/endpoint/windows_file_download_via_powershell.yml new file mode 100644 index 0000000000..f3b955ca23 --- /dev/null +++ b/detections/endpoint/windows_file_download_via_powershell.yml @@ -0,0 +1,122 @@ +name: Windows File Download Via PowerShell +id: 58c4e56c-b5b8-46a3-b5fb-6537dca3c6de +version: 1 +date: '2025-06-23' +author: Michael Haag, Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + The following analytic detects the use of PowerShell's download methods such as + "DownloadString" and "DownloadData" from the WebClient class or Invoke-WebRequest + and it's aliases "IWR" or "Curl". + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process execution logs that include command-line details. + This activity can be significant such methods and functions are commonly used in malicious + PowerShell scripts to fetch and execute remote code. + If confirmed malicious, this behavior could allow an attacker to download and run + arbitrary code, potentially leading to unauthorized access, data exfiltration, + or further compromise of the affected system. +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_powershell` + Processes.process IN ( + "*iwr *", "*Invoke-WebRequest*", "*wget *", + "curl", "*.DownloadData*", "*.DownloadFile*", + "*.DownloadString*" + ) + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec + Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_file_download_via_powershell_filter`' +how_to_implement: | + The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: | + False positives may be present and filtering will need to occur + by parent process or command line argument. It may be required to modify this query + to an EDR product for more granular coverage. +references: +- https://learn.microsoft.com/en-us/dotnet/api/system.net.webclient?view=net-9.0#methods +- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md +- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ +drilldown_searches: +- name: View the detection results for - "$user$" and "$dest$" + search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" and "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: File download activity initiated on $dest$ by user $user$. + $process_name$ was identified calling a download function $process$ + risk_objects: + - field: user + type: user + score: 56 + - field: dest + type: system + score: 56 + threat_objects: + - field: parent_process_name + type: parent_process_name + - field: process_name + type: process_name +tags: + analytic_story: + - Winter Vivern + - Phemedrone Stealer + - Malicious PowerShell + - Data Destruction + - SysAid On-Prem Software CVE-2023-47246 Vulnerability + - PHP-CGI RCE Attack on Japanese Organizations + - Hermetic Wiper + - IcedID + - Ingress Tool Transfer + - HAFNIUM Group + - XWorm + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1059.001 + - T1105 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test - Sysmon + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml index 41565e5f23..168a65c311 100644 --- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml +++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml @@ -1,7 +1,7 @@ name: Windows HTTP Network Communication From MSIExec id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 -version: 5 -date: '2025-05-02' +version: 6 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: Anomaly @@ -16,6 +16,7 @@ description: or further malware deployment. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_msiexec` by _time Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid @@ -80,6 +81,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec - Water Gamayun + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.007 @@ -89,8 +91,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: - - name: True Positive Test + - name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml index 7bf3fc26cb..4a5685d7dd 100644 --- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml +++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml @@ -1,7 +1,7 @@ name: Windows Ingress Tool Transfer Using Explorer id: 76753bab-f116-4ea3-8fb9-89b638be58a9 -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-07-01' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -17,17 +17,19 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = explorer.exe - OR Processes.original_file_name = explorer.exe) AND NOT (Processes.parent_process_name - IN("userinit.exe", "svchost.exe")) Processes.process IN ("* http://*", "* https://*") +search: | + | tstats `security_content_summariesonly` min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + (Processes.process_name = explorer.exe OR Processes.original_file_name = explorer.exe) + AND NOT (Processes.parent_process_name IN("userinit.exe", "svchost.exe")) + Processes.process IN ("* http://*", "* https://*") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_ingress_tool_transfer_using_explorer_filter`' + | `windows_ingress_tool_transfer_using_explorer_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index 7cd6f2a39c..cf57bf4aa5 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -1,10 +1,10 @@ name: Windows InstallUtil Remote Network Connection id: 4fbf9270-43da-11ec-9486-acde48001122 -version: 14 -date: '2025-05-02' +version: 15 +date: '2025-06-26' author: Michael Haag, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects the Windows InstallUtil.exe binary making a remote network connection. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and network telemetry. This activity is significant @@ -16,9 +16,12 @@ description: The following analytic detects the Windows InstallUtil.exe binary m of this activity. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 -search: |- +- Cisco Network Visibility Module Flow Data +search: | | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - where `process_installutil` by _time span=1h Processes.action Processes.dest Processes.original_file_name + where `process_installutil` + by _time span=1h + Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash @@ -29,8 +32,9 @@ search: |- | `security_content_ctime(lastTime)` | join process_id dest [| tstats `security_content_summariesonly` - count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != - 0 by All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in All_Traffic.bytes_out + count FROM datamodel=Network_Traffic.All_Traffic where + All_Traffic.dest_port != 0 + by All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in All_Traffic.bytes_out All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.dvc All_Traffic.protocol All_Traffic.protocol_version All_Traffic.src All_Traffic.src_ip All_Traffic.src_port All_Traffic.transport All_Traffic.user All_Traffic.vendor_product All_Traffic.direction All_Traffic.process_id @@ -38,9 +42,14 @@ search: |- | rename dest as command_and_control | rename src as dest] | table _time user src dest parent_process_name process_name process_path process process_id dest_port command_and_control - | stats count min(_time) as firstTime max(_time) as lastTime values(process) as process values(command_and_control) as command_and_control by user dest process_name process_id dest_port parent_process_name + | stats count min(_time) as firstTime + max(_time) as lastTime + values(process) as process + values(command_and_control) as command_and_control + by user dest process_name process_id dest_port parent_process_name | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)`| `windows_installutil_remote_network_connection_filter` + | `security_content_ctime(lastTime)` + | `windows_installutil_remote_network_connection_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -89,6 +98,7 @@ tags: - Living Off The Land - Compromised Windows Host - Signed Binary Proxy Execution InstallUtil + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.004 @@ -98,8 +108,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 9681700f1c..d76d0519e8 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil URL in Command Line id: 28e06670-43df-11ec-a569-acde48001122 -version: 10 -date: '2025-05-02' +version: 11 +date: '2025-02-03' author: Michael Haag, Splunk status: production type: TTP @@ -17,15 +17,21 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_installutil` Processes.process - IN ("*http://*","*https://*") by Processes.action Processes.dest Processes.original_file_name +- Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_installutil` + Processes.process IN ("*http://*","*https://*") + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_installutil_url_in_command_line_filter`' + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_installutil_url_in_command_line_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -75,6 +81,7 @@ tags: - Living Off The Land - Compromised Windows Host - Signed Binary Proxy Execution InstallUtil + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.004 @@ -84,8 +91,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index c4a17e03c1..aab60196f2 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -1,11 +1,11 @@ name: Windows MSIExec Remote Download id: 6aa49ff2-3c92-4586-83e0-d83eb693dfda -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-06-26' author: Michael Haag, Splunk status: production type: TTP -description: +description: | The following analytic detects the use of msiexec.exe with an HTTP or HTTPS URL in the command line, indicating a remote file download attempt. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process @@ -17,17 +17,22 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: - '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process - IN ("*http://*", "*https://*") by Processes.action Processes.dest Processes.original_file_name + - Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_msiexec` + Processes.process IN ("*http://*", "*https://*") + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_msiexec_remote_download_filter`' -how_to_implement: + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_msiexec_remote_download_filter` +how_to_implement: | The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -37,9 +42,8 @@ how_to_implement: the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: - False positives may be present, filter by destination or parent - process as needed. +known_false_positives: | + False positives may be present, filter by destination or parent process as needed. references: - https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md @@ -78,6 +82,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec - Water Gamayun + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.007 @@ -87,8 +92,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: - - name: True Positive Test + - name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml index 4154d3cde1..a40e4cd4ac 100644 --- a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml +++ b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned Child Process For Download id: f02b64b8-cbea-4f75-bf77-7a05111566b1 -version: 4 -date: '2025-05-02' +version: 5 +date: '2025-06-26' author: Teoderick Contreras, Splunk status: production type: TTP @@ -17,17 +17,26 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` - Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN - ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.action Processes.dest +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_office_products_parent` + Processes.process IN ("*http:*","*https:*") + NOT ( + Processes.original_file_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe") + OR + Processes.process_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe") + ) + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_office_product_spawned_child_process_for_download_filter`' + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_office_product_spawned_child_process_for_download_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, diff --git a/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml b/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml index 32be656d9a..de9a51d6eb 100644 --- a/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml +++ b/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml @@ -1,13 +1,17 @@ name: Windows PowerShell FakeCAPTCHA Clipboard Execution id: d81d4d3d-76b5-4f21-ab51-b17d5164c106 -version: 1 -date: '2025-05-14' +version: 2 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP -description: This detection identifies potential FakeCAPTCHA/ClickFix clipboard hijacking campaigns by looking for PowerShell execution with hidden window parameters and distinctive strings related to fake CAPTCHA verification. These campaigns use social engineering to trick users into pasting malicious PowerShell commands from their clipboard, typically delivering information stealers or remote access trojans. +description: | + This detection identifies potential FakeCAPTCHA/ClickFix clipboard hijacking campaigns by looking for PowerShell execution with hidden window parameters and distinctive strings related to fake CAPTCHA verification. These campaigns use social engineering to trick users into pasting malicious PowerShell commands from their clipboard, typically delivering information stealers or remote access trojans. data_source: - Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where `process_powershell` AND Processes.process="*-w*h*" @@ -72,6 +76,7 @@ rba: tags: analytic_story: - Fake CAPTCHA Campaigns + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1059.001 @@ -84,8 +89,13 @@ tags: security_domain: endpoint cve: [] tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/captcha_windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/wmic_xsl_execution_via_url.yml b/detections/endpoint/wmic_xsl_execution_via_url.yml index 238117825b..295d32087d 100644 --- a/detections/endpoint/wmic_xsl_execution_via_url.yml +++ b/detections/endpoint/wmic_xsl_execution_via_url.yml @@ -1,11 +1,12 @@ name: WMIC XSL Execution via URL id: 787e9dd0-4328-11ec-a029-acde48001122 -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-07-02' author: Michael Haag, Splunk status: production type: TTP -description: The following analytic detects `wmic.exe` loading a remote XSL script +description: | + The following analytic detects `wmic.exe` loading a remote XSL script via a URL. This detection leverages Endpoint Detection and Response (EDR) data, focusing on command-line executions that include HTTP/HTTPS URLs and the /FORMAT switch. This activity is significant as it indicates a potential application control @@ -14,20 +15,28 @@ description: The following analytic detects `wmic.exe` loading a remote XSL scri code, escalate privileges, or maintain persistence using a trusted Windows tool, posing a severe threat to the environment. data_source: -- Sysmon EventID 1 -- Windows Event Log Security 4688 -- CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_wmic` Processes.process - IN ("*http://*", "*https://*") Processes.process="*/format:*" by Processes.action - Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec - Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name - Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid - Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name - Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `wmic_xsl_execution_via_url_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection + - Sysmon EventID 1 + - Windows Event Log Security 4688 + - CrowdStrike ProcessRollup2 + - Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_wmic` + Processes.process IN ("*http://*", "*https://*") + Processes.process="*/format:*" + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path Processes.process + Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id + Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user + Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `wmic_xsl_execution_via_url_filter` +how_to_implement: | + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. @@ -36,26 +45,27 @@ how_to_implement: The detection is based on data that originates from Endpoint D the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: False positives are limited as legitimate applications typically - do not download files or xsl using WMIC. Filter as needed. +known_false_positives: | + False positives are limited as legitimate applications typically do not download files or xsl using WMIC. Filter as needed. references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md -- https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md#atomic-test-4---wmic-bypass-using-remote-xsl-file + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md + - https://web.archive.org/web/20190814201250/https://subt0x11.blogspot.com/2018/04/wmicexe-whitelisting-bypass-hacking.html + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1220/T1220.md#atomic-test-4---wmic-bypass-using-remote-xsl-file + - https://securitydatasets.com/notebooks/atomic/windows/defense_evasion/SDWIN-201017061100.html drilldown_searches: -- name: View the detection results for - "$user$" and "$dest$" - search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", - "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) - as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk - Message" values(analyticstories) as "Analytic Stories" values(annotations._all) - as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" - by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ + - name: View the detection results for - "$user$" and "$dest$" + search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$user$" and "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ utilizing wmic to download a remote XSL script. @@ -73,19 +83,25 @@ rba: type: process_name tags: analytic_story: - - Compromised Windows Host - - Suspicious WMI Use + - Compromised Windows Host + - Suspicious WMI Use + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - - T1220 + - T1220 product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1220/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1220/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata \ No newline at end of file diff --git a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml index 849a39dba9..fd3470330a 100644 --- a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml +++ b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml @@ -1,12 +1,12 @@ name: Cisco Secure Firewall - Repeated Malware Downloads id: aeff2bb5-3483-48d4-9be8-c8976194be1e -version: 2 -date: '2025-05-02' +version: 3 +date: '2025-07-01' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly description: | - The following analytic detects repeated malware file downloads initiated by the same internal host (src_ip) within a short time window. It leverages Cisco Secure Firewall Threat Defense logs and identifies `FileEvent` events with a `SHA_Disposition` of "Malware" and `FileDirection` set to "Download". If ten or more such events occur from the same host within five minutes, this analytic will trigger. This activity may indicate the host is compromised and repeatedly retrieving malicious content—either due to command-and-control, malware staging, or automation. If confirmed malicious, this behavior may represent an infection in progress, persistence mechanism, or a malicious downloader. + The following analytic detects repeated malware file downloads initiated by the same internal host (src_ip) within a short time window. It leverages Cisco Secure Firewall Threat Defense logs and identifies `FileEvent` events with a `SHA_Disposition` of "Malware" and `FileDirection` set to "Download". If ten or more such events occur from the same host within five minutes, this analytic will trigger. This activity may indicate the host is compromised and repeatedly retrieving malicious content either due to command-and-control, malware staging, or automation. If confirmed malicious, this behavior may represent an infection in progress, persistence mechanism, or a malicious downloader. data_source: - Cisco Secure Firewall Threat Defense File Event search: | diff --git a/lookups/attacker_tools.csv b/lookups/attacker_tools.csv index c7a5bf78b8..dcad4d40c7 100644 --- a/lookups/attacker_tools.csv +++ b/lookups/attacker_tools.csv @@ -1,38 +1,35 @@ attacker_tool_names,description -remcom.exe,This process is an open source replacement to psexec and is not typically seen in an enterprise environment. -pwdump.exe,This process is associated with a tool used to dump password hashes on a Windows system. -pwdump2.exe,This process is associated with a tool used to dump password hashes on a Windows system. -nc.exe,This process is an open source tool used for network communications. -wce.exe,This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks. +advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports. cain.exe,This process is associated with a tool used to collect user credentials and execute attacks. -nmap.exe,This process is an open source network mapping tool used to identify hosts and listening services on a network. -kidlogger.exe,This process is associated with a tool used to collect keyboard input on a host. -isass.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. -svch0st.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. -at.exe,This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility. +certify.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) +certipy.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) +fscan.exe,Fscan is a tool used to scan for open ports and services on a network. getmail.exe,This process is seen to be used by attackers to extract email files from host machines. -ntdll.exe,This process was identified as malicious by DHS Alert TA18-074A. -netpass.exe,This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user. -WebBrowserPassView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers. -OutlookAddressBookView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook. +isass.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. +kidlogger.exe,This process is associated with a tool used to collect keyboard input on a host. +KPortScan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks. mailpv.exe,This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients. -NLBrute.exe,A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords. -selfdel.exe,This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities. masscan.exe,This executable was delivered in the XMRig Crypto Miner Massscan_GUI.exe,This executable was delivered in the XMRig Crypto Miner -KPortScan3.exe,This executable was delivered in the XMRig Crypto Miner and is commonly used by attackers to scan the internet +mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets. +nc.exe,This process is an open source tool used for network communications. +netpass.exe,This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user. NLAChecker.exe,A scanner tool that checks for Windows hosts for Network Level Authentication. This tool allows attackers to detect Windows Servers with RDP without NLA enabled which facilitates the use of brute force non microsoft rdp tools or exploits +NLBrute.exe,A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords. +nmap.exe,This process is an open source network mapping tool used to identify hosts and listening services on a network. ns.exe,A commonly used tool used by attackers to scan and map file shares -SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts. -kportscan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks. -advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports. -mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets. -certify.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) -certipy.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) -ladon.exe,Ladon is a multi-threaded plug-in comprehensive scanning artifact for large-scale network penetration including port scanning service identification network assets password explosion high-risk vulnerability detection and one click getshell. -sharpTask.exe,SharpTask is a tool that allows you to create scheduled tasks on a Windows system. -SharpHide.exe,SharpHide is a tool that allows you to hide a process from the task manager. -SharpStay.exe,SharpStay is a tool that allows you to stay hidden from the task manager. +ntdll.exe,This process was identified as malicious by DHS Alert TA18-074A. +OutlookAddressBookView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook. +pwdump.exe,This process is associated with a tool used to dump password hashes on a Windows system. +pwdump2.exe,This process is associated with a tool used to dump password hashes on a Windows system. +remcom.exe,This process is an open source replacement to psexec and is not typically seen in an enterprise environment. seatbelt.exe,A tool used to collect detailed information about a system—such as remote access configurations network shares and other security-relevant data on victim machine. +selfdel.exe,This executable was delivered in the SamSam Ransomware Campaign and the attackers leveraged this binary to delete its malicious activities. SharpGPOAbuse.exe,SharpGPOAbuse is a tool that allows you to abuse and enumerate GPOs on a Windows system. -fscan.exe,Fscan is a tool used to scan for open ports and services on a network. \ No newline at end of file +SharpHide.exe,SharpHide is a tool that allows you to hide a process from the task manager. +SharpStay.exe,SharpStay is a tool that allows you to stay hidden from the task manager. +sharpTask.exe,SharpTask is a tool that allows you to create scheduled tasks on a Windows system. +SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts. +svch0st.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. +wce.exe,This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks. +WebBrowserPassView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers. diff --git a/lookups/attacker_tools.yml b/lookups/attacker_tools.yml index dfbe78b94e..ede9b5d417 100644 --- a/lookups/attacker_tools.yml +++ b/lookups/attacker_tools.yml @@ -1,6 +1,6 @@ name: attacker_tools -date: 2025-03-18 -version: 3 +date: 2025-06-23 +version: 4 id: 72620fe1-26cb-4cee-a6ee-8c6127056d81 author: Splunk Threat Research Team lookup_type: csv @@ -8,4 +8,4 @@ description: A list of tools used by attackers match_type: - WILDCARD(attacker_tool_names) min_matches: 1 -case_sensitive_match: false \ No newline at end of file +case_sensitive_match: false diff --git a/lookups/suspicious_ports_list.csv b/lookups/suspicious_ports_list.csv new file mode 100644 index 0000000000..9314c3f120 --- /dev/null +++ b/lookups/suspicious_ports_list.csv @@ -0,0 +1,86 @@ +dest_port,comment,confidence,category +801,manjusaka (cobalstrike chinese clone) default panel ui,medium,malware +1005,Nitedrem trojan Downloader + Pest + Theef,medium,malware +1015,Doly trojan,high,malware +1042,Bla trojan,high,malware +1075,Backdoor.Win32.LanaFTP.k listening on this port,high,malware +1080,Was seen being used by multiple malware and is also the default port of the pentest utility ligolo,medium,C2 +1170,Psyber Stream Server - PSS,high,malware +1243,SubSeven backdoor,high,malware +1337,Was seen being used by multiple malware and red team or pentest utilities such as empire; crackmapexec; icebreaker; KittyStager; Cyberghost VPN; gophish; gtunnel. The port is also associated with various other types of exploits or shellcode,high,exploitation +1981,Shockrave malware,high,malware +2001,Millennium Worm and multiple malwares,medium,malware +2773,SubSeven trojan and some backup services,medium,malware +2989,Multiple RAT instances were seen using this port,high,malware +3000,ptunnel-ng + beefproject http panel default port,medium,C2 +3024,WinCrash trojan,high,malware +3030,nuages C2 default port and other malwares,high,C2 +3129,Master's Paradise trojan,high,malware +3200,manjusaka (cobalstrike chinese clone) default panel ui,medium,C2 +3333,gophish + Xmrig coinminer,high,Cryptominer +3410,Optix Pro trojan,high,malware +3790,often used for metasploit but also legit service like quickbooksrds,high,C2 +4000,ptunnel-ng + multiple malwares and RAT but also some legit usages,medium,C2 +4041,Masters Paradise trojan,high,malware +4051,AlanFramework C2 default port but also used by cisco P2P,high,C2 +4092,WinCrash trojan,high,malware +4433,AlanFramework C2 default port and Acidoor backdoor,high,C2 +4444,Default listener port for Metasploit exploits and RemotePC transfer port and gophish,high,C2 +4567,PrimusC2 + File Nail trojan and legit usage for verizon,medium,C2 +4590,ICQTrojan,high,malware +4747,RPC-Backdoor - RPC over TCP/IP with the hard-coded port number 4747,medium,Persistence +5000,hardhatC2 and HRShell default port + other malwares and legit usages,medium,C2 +5001,FudgeC2 + spiderfoot and other malwares but also used by synology NAS and yahoo messenger,medium,C2 +5096,hardhatC2 default port,high,C2 +5321,Firehotcker trojan,high,malware +5400,BladeRunner and Back Construction trojans but also some games,medium,malware +5556,AlanFramework C2 default port and H0rtiga trojan,high,C2 +6666,kali default port - IRC botnets and RAT - CVE-2024-38112/Void Banshee,high,exploitation +6667,IRC channel used by botnet and multiple malwares but also legit usages,medium,malware +6722,default port for socks reverse proxy of XiebroC2,high,C2 +7096,hardhatC2 default port and other legit usages,high,C2 +7444,mythic C2 default port and legit vmware port,medium,C2 +7474,default port for bloodhound neo4j,medium,exploitation +7681,Supershell C2 default port,high,C2 +7682,Supershell C2 default port,high,C2 +7687,Neo4j default port,medium,exploitation +7712,cobaltstrike samples wih lumma stealer used this port,medium,C2 +7844,cloudfare tunnel,high,C2 +8022,MaccaroniC2 default port,high ,C2 +8848,DcRat,medium,malware +8888,POSHC2 default port but also legit usages,medium,exploitation +8936,MoonPeak malware,medium,C2 +8999,PrimusC2,medium,malware +9631,hardhatC2 default port and other legit usages,high,C2 +9936,MoonPeak malware,medium,C2 +9966,MoonPeak malware,medium,C2 +9988,Rbot-GR trojan and other legit usages,medium,malware +10002,multiple malwares,medium,malware +10426,Backdoor.Win32.Agent.cu,medium,malware +12122,Backdoor.Hellza server listening on this port,medium,malware +12345,netbus trojan and other malwares,high,malware +12346,netbus trojan and other malwares,high,malware +13333,Xmrig coinminer,high,Cryptominer +15555,Xmrig coinminer,high,Cryptominer +17300,Kuang2 trojan,high,malware +19999,Xmrig coinminer,high,Cryptominer +20034,netbus trojan and other malwares,high,malware +21802,HardhatC2 default port,high,C2 +27374,SubSeven backdoor and multiple other malwares,high,malware +30662,o365-attack-toolkit default port,high,exploitation +31335,Trinoo distributed attack tool port,high,exploitation +31337,Associated with various types of exploits; shellcode and command and control servers such as SliverC2. Also serves as ThunderShell default port; and was seen used by Back Orifice backdoor.,high,C2 +31338,Was seen being used by the Back Orifice backdoor and other malwares,high,malware +31785,Hack’a’Tack RAT,high,malware +31789,Hack’a’Tack RAT,high,malware +35000,evilqr,medium,exploitation +48101,W32.Blastclan.Worm,high,malware +50050,Sharpc2 and CobaltStrike default port,high,C2 +50501,TEMP.Veles used port-protocol mismatches on ports such as 443 - 4444 - 8531 and 50501 during C2,high,C2 +52935,C3 webcontroller default port,medium,C2 +53531,dnscat2 default port,high,C2 +54320,Back Orifice backdoor,medium,malware +55553,Metasploit RPC daemon default port; also used by Armitage team server,high,exploitation +57230,Covenant C2 default port,high,C2 +61466,Backdoor:Win32/Thething.F and telecommando trojan,medium,malware +65000,Devil RAT,medium,malware diff --git a/lookups/suspicious_ports_list.yml b/lookups/suspicious_ports_list.yml new file mode 100644 index 0000000000..4b060e9916 --- /dev/null +++ b/lookups/suspicious_ports_list.yml @@ -0,0 +1,11 @@ +name: suspicious_ports_list +date: 2025-07-01 +version: 1 +id: 5fa401d1-f0d4-4a6d-b3e4-db7cc45acc28 +author: mthcht, Splunk Threat Research Team +lookup_type: csv +description: A list of suspicious ports that are used or abused by threat actors, malware or PUA software. +match_type: +- WILDCARD(file) +min_matches: 1 +case_sensitive_match: false diff --git a/lookups/typo_squatted_python_packages.csv b/lookups/typo_squatted_python_packages.csv new file mode 100644 index 0000000000..2242a44372 --- /dev/null +++ b/lookups/typo_squatted_python_packages.csv @@ -0,0 +1,569 @@ +typosquatted_package_name,comment,package_official_url +*aasyncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*assyncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyincio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncci*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynccio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynci*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncii*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynciio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncioi*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncioo*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynciooo*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyyncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*aysncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*beaitifulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaitifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaotifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaufifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaurifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifilsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifilsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautiflulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautiflulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifolsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifoulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifuklsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifuksoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifullsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifullsooup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoul*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoupe*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoupo*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifuosoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautilfulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautyfulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautysoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beuatiflsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beutifullsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beutifulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*bibp-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*biip-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-u8ls*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uitls*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-util*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilds*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utile*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utiles*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilos*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilss*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilz*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utisl*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utjls*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utlils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uttils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uutils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bipp-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bips-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*biup-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bop-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bpi-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bup-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bupi-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*capmoneercloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsstercloudcliennt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsstercloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterccloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclenet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclenit*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliant*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclieent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclieet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclien*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliend*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliendt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclienet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliennt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclientt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclinent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclinet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclouidclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcluodclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouddclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouddlient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouidclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercludclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercoudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercouldclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterrcloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmosterclouclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclieent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclienet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclinet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*cilorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*clolorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*cloroma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colaroma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colomara*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorahma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramae*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramah*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramal*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramaz*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorame*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramia*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramka*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramna*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramo*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramoo*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramqa*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramqs*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramu*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramwa*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramws*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramxa*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramxs*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramza*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramzs*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorayma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorhrama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorm*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colormma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloroama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorram*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorramma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colouorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colprama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*corlorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*cstmotkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cuatomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cusgtomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cusromtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custm*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custmtokinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custogtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custohtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custojmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custojtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custoktkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customekinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtikinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtiknter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtjinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkfnter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkibter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkihter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkimter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinber*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinet*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinetr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinger*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkingter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinrer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintar*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinte*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinted*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinteer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintert*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintet*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintre*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintrer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintrr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintwr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinyer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitenr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkiter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitner*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitnerr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitnre*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkiyter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkjnter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkknter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkniter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkniterr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtknster*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtknter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkwnter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkznter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custontkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custoqtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotkminter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotminter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custoumtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custpmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custrmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custumtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custvomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cutomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cuwtomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cuxtomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*maptplotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplftlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpliotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplkotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpllotb*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpllotib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplolplib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matploltlab*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matploltlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplootib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matploptlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplorlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotblib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotkib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotklib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlbib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlig*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotllib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlob*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlpib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlr*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotltib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlub*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlyib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotoib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotpib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplottbib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplottib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplottlab*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotvib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotvlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplptlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplrtib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplrtlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpltotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplttlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplutlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*oillow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*p-cord*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*p8llow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*p9llow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pi-cord*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilkow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pill9w*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilliow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilliw*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pillkw*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pillo2*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilloa*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilloo*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilloq*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pillox*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilpow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*piolow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*piplow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pirlow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pjllow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*plaawright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/ " +*plauwright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plawwright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plawyright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playrwight*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwirght*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrght*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrgiht*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrgith*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrigght*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrigh*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrightt*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrigth*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrihgt*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwritgh*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plyawright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plywright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*pollow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pqtorch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pttorch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pullow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*py-c0ard*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c0crd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c0dd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c0red*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c9rd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cdord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cird*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-ckord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-ckrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-co4d*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coad*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cobrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cocd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cod*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-codrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coed*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coerd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cofd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cofrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coird*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cojrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coordd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coqrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corad*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corddd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corde*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordf*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordq*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordr*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordv*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordw*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordx*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corf*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corfd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corg*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corid*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cortd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corwd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corx*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corxd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cotd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cotrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cowrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cozd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cpord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cprd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-crd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-crodd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cwrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cxrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cyrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-czrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-vord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-xord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pycjrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pycordde*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pycordwd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pygacme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaeme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaime*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamke*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamm*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamne*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamr*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamse*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamw*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygane*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaome*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaqme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygarme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygawme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygazme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygfame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygfme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pyghame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygmme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygqame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygqme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygume*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygvame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygxme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygzme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pzgame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pytarch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytbrch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytcrch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pythrch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytirch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytlrc*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytoich*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorbch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcb*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcdh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchb*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchc*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchg*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchj*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchv*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchy*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcm*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcu*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytordh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorqh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytprch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytroce*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytrosh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pztorch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*rensoflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*reqeist*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeosts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeuste*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeustx*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeustz*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeyst*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqirements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiremnets*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiremnts*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiurements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiurementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiuremnets*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqjuests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqoests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqquest*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqsests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requas*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requeits*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requeksts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requekts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requeqsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesgt*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesks*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesqs*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesrts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requestr*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesuts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesxs*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesxt*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesxts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requetsa*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requetsq*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requetsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requewsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requiements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requierement*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requierments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirementstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirementsxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiiremments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiiremnts*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremants*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremeents*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremenstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremenstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementss*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementst*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementsttx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxtt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxtx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementtsxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxtt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetns*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetnstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremmentstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremmentxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremmentxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnets*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnetstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnetxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnts*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremntstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremntstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremntxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremtns*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmeents*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirment*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentss*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentstxtt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirrementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirtements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiurement*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiurementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requksts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requnests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requrementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requriements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requriments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requssts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requstss*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requxsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requyests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requzsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqzests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reuirements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*seleenim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleenimu*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleeniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleinium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleiniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleinuim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleiumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemiumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemni*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemnim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemnium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenimn*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selennim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selennuim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenuimm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenyum*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleunium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seliniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seliniumn*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selinum*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selleium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selleniium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*sellenim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selleniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*sellinium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selunium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*sijplejso*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*sijplejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simepljson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simolejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpejso*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpjson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpkejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejason*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejdon*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejsoh*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejsoj*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpoejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*siplejason*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*sjimplejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*sjmplejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*temsorflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensnflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensobflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofklow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofl9w*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofla*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflaow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofleow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofliw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofllow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofloaw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflod*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflolw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflom*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflomw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflonw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflor*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflouw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflpw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflqw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflsw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflxow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofpow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensogflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensourflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensxoflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*trnsorflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*pyquest*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*ultrarequests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" diff --git a/lookups/typo_squatted_python_packages.yml b/lookups/typo_squatted_python_packages.yml new file mode 100644 index 0000000000..676f4a7d9e --- /dev/null +++ b/lookups/typo_squatted_python_packages.yml @@ -0,0 +1,11 @@ +name: typo_squatted_python_packages +date: 2025-07-05 +version: 1 +id: cd309a8c-90d8-4c0d-98bf-70e8f5296a1e +author: Nasreddine Bencherchali, Splunk Threat Research Team +lookup_type: csv +description: A list of known typo squatted python packages +match_type: +- WILDCARD(typosquatted_package_name) +min_matches: 1 +case_sensitive_match: false diff --git a/macros/cisco_network_visibility_module_flowdata.yml b/macros/cisco_network_visibility_module_flowdata.yml new file mode 100644 index 0000000000..eb93ad8dd8 --- /dev/null +++ b/macros/cisco_network_visibility_module_flowdata.yml @@ -0,0 +1,3 @@ +definition: sourcetype="cisco:nvm:flowdata" +description: customer specific splunk configurations(eg- index, source, sourcetype) for Cisco Network Visibility Module flow logs. Replace the macro definition with configurations for your Splunk Environment. +name: cisco_network_visibility_module_flowdata diff --git a/removed/deprecation_mapping.YML b/removed/deprecation_mapping.YML index 76db545adf..69417fd8e3 100644 --- a/removed/deprecation_mapping.YML +++ b/removed/deprecation_mapping.YML @@ -1,4 +1,19 @@ detections: + - content: Windows InstallUtil Uninstall Option with Network + removed_in_version: 5.12.0 + reason: Detection has been deprecated as its scope is already covered by "Windows InstallUtil Remote Network Connection". + replacement_content: + - Windows InstallUtil Remote Network Connection + - content: Any Powershell DownloadString + removed_in_version: 5.12.0 + reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management. + replacement_content: + - Windows File Download Via PowerShell + - content: Any Powershell DownloadFile + removed_in_version: 5.12.0 + reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management. + replacement_content: + - Windows File Download Via PowerShell - content: Windows AD Suspicious GPO Modification removed_in_version: 5.10.0 reason: Detection deprecated due to lack of data and consistency. Research is being done to create potential replacement in a future release. diff --git a/stories/cisco_network_visibility_module_analytics.yml b/stories/cisco_network_visibility_module_analytics.yml new file mode 100644 index 0000000000..bf9d3b0aff --- /dev/null +++ b/stories/cisco_network_visibility_module_analytics.yml @@ -0,0 +1,27 @@ +name: Cisco Network Visibility Module Analytics +id: cf276930-de9f-484c-9d92-f358534890a1 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +description: | + This analytic story provides a suite of detections built to analyze endpoint-based network telemetry captured by the Cisco Network Visibility Module (NVM). + It focuses on identifying suspicious and potentially malicious activity such as process injection, unauthorized downloads, network connections by non-network-aware processes, and potential command-and-control (C2) behavior, etc. + Leveraging the rich metadata from NVM, including process names, command-line arguments, user context, and module information, these detections provide high-fidelity insights into host behavior and outbound network activity. +narrative: | + Cisco Network Visibility Module (NVM), part of Cisco Secure Client (formerly AnyConnect), collects granular telemetry directly from endpoints to provide enhanced visibility into process-level network activity. + This includes detailed fields such as process names, parent-child relationships, command-line arguments, loaded modules, user accounts, and DNS destinations. + This analytic story leverages that context to detect threats across various tactics and techniques including Command and Control, Execution, Defense Evasion, and Credential Access. + It is particularly useful for detecting living-off-the-land (LOLBins) behavior, abuse of legitimate system processes, or exfiltration attempts from otherwise trusted binaries. +references: +- https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect42/administration/guide/b_AnyConnect_Administrator_Guide_4-2/b_AnyConnect_Administrator_Guide_4-2_chapter_01100.pdf +- https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/Cisco-Secure-Client-5/admin/guide/nvm-collector-5-1-1-admin-guide.html +- https://community.cisco.com/t5/security-knowledge-base/cisco-network-visibility-nvm-collector/ta-p/4309825 +tags: + category: + - Adversary Tactics + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection