From f49bd318d9a8620e36a48fa6c79bfe0888b08962 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 30 Jun 2025 13:55:55 +0200 Subject: [PATCH 01/21] =?UTF-8?q?update=20time=20=F0=9F=9A=80?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...o_network_visibility_monitor_flow_data.yml | 149 ++++++++++++++++++ ...sco_network_visibility_monitor_osquery.yml | 51 ++++++ .../any_powershell_downloadfile.yml | 6 +- .../any_powershell_downloadstring.yml | 6 +- ...tallutil_uninstall_option_with_network.yml | 6 +- .../endpoint/attacker_tools_on_endpoint.yml | 12 +- .../endpoint/bitsadmin_download_file.yml | 8 +- .../detect_html_help_url_in_command_line.yml | 12 +- .../detect_mshta_url_in_command_line.yml | 12 +- .../suspicious_curl_network_connection.yml | 1 - ...ndows_curl_download_to_suspicious_path.yml | 12 +- ...dows_curl_upload_to_remote_destination.yml | 12 +- .../windows_file_download_via_certutil.yml | 12 +- .../windows_file_download_via_powershell.yml | 121 ++++++++++++++ ...ttp_network_communication_from_msiexec.yml | 12 +- ..._installutil_remote_network_connection.yml | 34 ++-- ...indows_installutil_url_in_command_line.yml | 25 ++- .../windows_msiexec_remote_download.yml | 35 ++-- ...uct_spawned_child_process_for_download.yml | 25 ++- lookups/attacker_tools.csv | 53 +++---- lookups/attacker_tools.yml | 6 +- removed/deprecation_mapping.YML | 15 ++ 22 files changed, 521 insertions(+), 104 deletions(-) create mode 100644 data_sources/cisco_network_visibility_monitor_flow_data.yml create mode 100644 data_sources/cisco_network_visibility_monitor_osquery.yml rename detections/{endpoint => deprecated}/any_powershell_downloadfile.yml (98%) rename detections/{endpoint => deprecated}/any_powershell_downloadstring.yml (98%) rename detections/{endpoint => deprecated}/windows_installutil_uninstall_option_with_network.yml (99%) create mode 100644 detections/endpoint/windows_file_download_via_powershell.yml diff --git a/data_sources/cisco_network_visibility_monitor_flow_data.yml b/data_sources/cisco_network_visibility_monitor_flow_data.yml new file mode 100644 index 0000000000..819533b02d --- /dev/null +++ b/data_sources/cisco_network_visibility_monitor_flow_data.yml @@ -0,0 +1,149 @@ +name: Cisco Network Visibility Module Flow Data +id: d49bcd3c-da06-41c6-b33e-8b8d23078f68 +version: 1 +date: '2025-06-30' +author: Nasreddine Bencherchali, Splunk +description: Data source object for Netflow events from Cisco Network Visibility Module +source: not_applicable +sourcetype: cisco:nvm:flowdata +supported_TA: +- name: Cisco Security Cloud + url: https://splunkbase.splunk.com/app/4221 + version: 4.0.7 +fields: +- action +- aditional_logged_in_user_list +- aliul +- bytes +- bytes_in +- bytes_out +- da +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- deserialize +- dest +- dest_hostname +- dest_ip +- dest_ipv6 +- dest_port +- dh +- direction +- dp +- dps +- ds +- eventtype +- fd +- fems +- fes +- fet +- field +- flow_dns_suffix +- flow_end_msec +- flow_end_sec +- flow_end_time +- flow_report_stage +- flow_start_msec +- flow_start_sec +- flow_start_time +- flow_version +- fsg +- fsms +- fss +- fst +- fv +- hh +- hm +- host +- ht +- http_host +- http_method +- ibc +- iid +- index +- linecount +- liuat +- liuid +- liuida +- liuidp +- logged_in_user +- logged_in_user_account_type +- logged_in_user_authority +- logged_in_user_principal +- mhl +- mnl +- module_hash_list +- module_name_list +- obc +- pa +- paa +- pap +- parent_process +- parent_process_account +- parent_process_arguments +- parent_process_hash +- parent_process_id +- parent_process_integrity_level +- parent_process_name +- parent_process_path +- parent_process_user_account_type +- parg +- ph +- pid +- pil +- pn +- ppa +- pparg +- ppath +- pph +- ppid +- ppil +- ppn +- pppath +- ppuat +- pr +- process +- process_account_authority +- process_account_principal +- process_arguments +- process_guid +- process_hash +- process_id +- process_integrity_level +- process_name +- process_path +- process_user_account_type +- protocol_identifier +- puat +- puid +- punct +- sa +- source +- sourcetype +- sp +- splunk_server +- splunk_server_group +- sps +- src +- src_interface +- src_ip +- src_ipv6 +- src_port +- tag +- tag::action +- tag::eventtype +- timeendpos +- timestamp +- timestartpos +- transport +- udid +- uri_path +- user +output_fields: +- dest +example_log: 'Jun 26 16:09:18 127.0.0.1 Jun 26 16:09:18 ip-172-31-30-201 fv="nvzFlow_v9" pr="6" sa="172.16.3.110" sp="5203" da="140.82.112.3" dp="443" fd="1" fss="1750954134" fst="Thu Jun 26 16:08:54 2025" fes="1750954134" fet="Thu Jun 26 16:08:54 2025" hh="''" hm="''" ht="''" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" liuid="EC2AMAZ-E56LIG5\Administrator" liuida="EC2AMAZ-E56LIG5" liuidp="Administrator" liuat="2" pa="EC2AMAZ-E56LIG5\Administrator" paa="EC2AMAZ-E56LIG5" pap="Administrator" puat="8194" pn="msiexec.exe" ph="23EC37A4DF21893A1B3B6F5F72B2D78918E86C3A90F9664F8248A2C8219F889A" ppa="EC2AMAZ-E56LIG5\Administrator" ppuat="8194" ppn="cmd.exe" pph="41871DADE953D9F40F4AA445FC19982AB59D263C8AA93D7F67A1451663A09A57" ibc="0" obc="0" ds="us-east-2.compute.internal" dh="github.com" iid="4" mnl="''" mhl="''" fsms="1750954134331" fems="1750954134340" pid="8496" ppath="C:\Windows\system32\msiexec.exe" parg=" /i \"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1218.007/src/T1218.007_JScript.msi\"" ppid="9232" pppath="C:\Windows\system32\cmd.exe" aliul="''" pil="12288" ppil="12288" fsg="1" puid="071161F29663831BB4A1C0FADA9805E0"' diff --git a/data_sources/cisco_network_visibility_monitor_osquery.yml b/data_sources/cisco_network_visibility_monitor_osquery.yml new file mode 100644 index 0000000000..098daf00a7 --- /dev/null +++ b/data_sources/cisco_network_visibility_monitor_osquery.yml @@ -0,0 +1,51 @@ +name: Cisco Network Visibility Module OSquery +id: d59bcd3c-da06-41c6-b33e-8b8d23078f68 +version: 1 +date: '2025-06-30' +author: Nasreddine Bencherchali, Splunk +description: Data source object for OSquery events from Cisco Network Visibility Module +source: not_applicable +sourcetype: cisco:nvm:osquery +supported_TA: +- name: Cisco Security Cloud + url: https://splunkbase.splunk.com/app/4221 + version: 4.0.7 +fields: +- current_page +- date_hour +- date_mday +- date_minute +- date_month +- date_second +- date_wday +- date_year +- date_zone +- eventtype +- fv +- host +- index +- linecount +- osquery_version +- punct +- qid +- qjr +- qpi +- qpn +- qt +- query_id +- query_json_response +- query_timestamp +- qv +- source +- sourcetype +- splunk_server +- splunk_server_group +- tag +- tag::eventtype +- timeendpos +- timestartpos +- total_pages +- udid +output_fields: +- query_json_response +example_log: 'Jun 30 09:20:43 127.0.0.1 Jun 30 09:20:43 ip-172-31-30-201 fv="nvzFlow_v8" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" qv="5.5.1-dirty" qid="38654705666" qt="1751275242" qpi="1" qpn="1" qjr="[{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"addons-search-detection@mozilla.com\",\"location\":\"app-builtin\",\"name\":\"Add-ons Search Detection\",\"native\":\"\",\"path\":\"null\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.0.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Mozilla \",\"description\":\"Take clips and screenshots from the Web and save them temporarily or permanently.\",\"disabled\":\"1\",\"identifier\":\"screenshots@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Firefox Screenshots\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\screenshots@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"39.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"formautofill@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Form Autofill\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\formautofill@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Fixes for web compatibility with Picture-in-Picture\",\"disabled\":\"0\",\"identifier\":\"pictureinpicture@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Picture-In-Picture\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\pictureinpicture@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.0\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Urgent post-release fixes for web compatibility.\",\"disabled\":\"0\",\"identifier\":\"webcompat@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Web Compatibility Interventions\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"137.7.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Thomas Wisniewski \",\"description\":\"Report site compatibility issues on webcompat.com\",\"disabled\":\"1\",\"identifier\":\"webcompat-reporter@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"WebCompat Reporter\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat-reporter@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.1.0\",\"visible\":\"1\"}]"' \ No newline at end of file diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/deprecated/any_powershell_downloadfile.yml similarity index 98% rename from detections/endpoint/any_powershell_downloadfile.yml rename to detections/deprecated/any_powershell_downloadfile.yml index 0696a658c8..20d9e8c712 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/deprecated/any_powershell_downloadfile.yml @@ -1,9 +1,9 @@ name: Any Powershell DownloadFile id: 1a93b7ea-7af7-11eb-adb5-acde48001122 -version: '15' -date: '2025-05-06' +version: '16' +date: '2025-06-23' author: Michael Haag, Splunk -status: production +status: deprecated type: TTP description: The following analytic detects the use of PowerShell's `DownloadFile` method to download files. It leverages data from Endpoint Detection and Response diff --git a/detections/endpoint/any_powershell_downloadstring.yml b/detections/deprecated/any_powershell_downloadstring.yml similarity index 98% rename from detections/endpoint/any_powershell_downloadstring.yml rename to detections/deprecated/any_powershell_downloadstring.yml index 48464928ef..d477fd6d7e 100644 --- a/detections/endpoint/any_powershell_downloadstring.yml +++ b/detections/deprecated/any_powershell_downloadstring.yml @@ -1,9 +1,9 @@ name: Any Powershell DownloadString id: 4d015ef2-7adf-11eb-95da-acde48001122 -version: '12' -date: '2025-05-06' +version: '13' +date: '2025-06-23' author: Michael Haag, Splunk -status: production +status: deprecated type: TTP description: The following analytic detects the use of PowerShell's `DownloadString` method to download files. It leverages data from Endpoint Detection and Response diff --git a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml b/detections/deprecated/windows_installutil_uninstall_option_with_network.yml similarity index 99% rename from detections/endpoint/windows_installutil_uninstall_option_with_network.yml rename to detections/deprecated/windows_installutil_uninstall_option_with_network.yml index f65912f4fa..de81a547e1 100644 --- a/detections/endpoint/windows_installutil_uninstall_option_with_network.yml +++ b/detections/deprecated/windows_installutil_uninstall_option_with_network.yml @@ -1,9 +1,9 @@ name: Windows InstallUtil Uninstall Option with Network id: 1a52c836-43ef-11ec-a36c-acde48001122 -version: 12 -date: '2025-05-02' +version: 13 +date: '2025-06-26' author: Michael Haag, Splunk -status: production +status: deprecated type: TTP description: The following analytic identifies the use of Windows InstallUtil.exe making a remote network connection using the `/u` (uninstall) switch. This detection diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 4776b63799..c8b5d61cff 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,7 +1,7 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 11 -date: '2025-05-02' +version: 12 +date: '2025-06-30' author: Bhavin Patel, Splunk status: production type: TTP @@ -17,6 +17,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process values(Processes.parent_process) as parent_process from datamodel=Endpoint.Processes where Processes.dest!=unknown @@ -87,8 +88,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/bitsadmin_download_file.yml b/detections/endpoint/bitsadmin_download_file.yml index cc606ede9b..e4c528392f 100644 --- a/detections/endpoint/bitsadmin_download_file.yml +++ b/detections/endpoint/bitsadmin_download_file.yml @@ -1,7 +1,7 @@ name: BITSAdmin Download File id: 80630ff4-8e4c-11eb-aab5-acde48001122 -version: 10 -date: '2025-05-02' +version: 11 +date: '2025-06-24' author: Michael Haag, Sittikorn S status: production type: TTP @@ -90,12 +90,12 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog -- name: True Positive Test +- name: True Positive Test - CrowdStrike attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log source: crowdstrike diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 49584331fd..56e9278994 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect HTML Help URL in Command Line id: 8c5835b9-39d9-438b-817c-95f14c69a31e -version: 11 -date: '2025-05-02' +version: 12 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP @@ -16,6 +16,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_hh` Processes.process=*http* by Processes.action Processes.dest Processes.original_file_name Processes.parent_process @@ -87,8 +88,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 8699348b29..70a2978c99 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Detect MSHTA Url in Command Line id: 9b3af1e6-5b68-11eb-ae93-0242ac130002 -version: 13 -date: '2025-05-19' +version: 14 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP @@ -16,6 +16,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_mshta` (Processes.process="*http://*" @@ -89,8 +90,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/suspicious_curl_network_connection.yml b/detections/endpoint/suspicious_curl_network_connection.yml index 9202695dbc..22c426f43c 100644 --- a/detections/endpoint/suspicious_curl_network_connection.yml +++ b/detections/endpoint/suspicious_curl_network_connection.yml @@ -38,7 +38,6 @@ how_to_implement: The detection is based on data that originates from Endpoint D known_false_positives: Unknown. Filter as needed. references: - https://redcanary.com/blog/clipping-silver-sparrows-wings/ -- https://www.marcosantadev.com/manage-plist-files-plistbuddy/ rba: message: Suspicious usage of curl on $dest$ risk_objects: diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index ed5a43f75b..aeaf1addd1 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -1,7 +1,7 @@ name: Windows Curl Download to Suspicious Path id: c32f091e-30db-11ec-8738-acde48001122 -version: 13 -date: '2025-05-02' +version: 14 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP @@ -17,6 +17,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_curl` Processes.process IN ("*-O *","*--output*") Processes.process IN ("*\\appdata\\*","*\\programdata\\*","*\\public\\*") @@ -89,8 +90,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 41187a45f9..dd512af657 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -1,7 +1,7 @@ name: Windows Curl Upload to Remote Destination id: 42f8f1a2-4228-11ec-aade-acde48001122 -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-06-20' author: Michael Haag, Splunk status: production type: TTP @@ -16,6 +16,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_curl` Processes.process IN ("*-T *","*--upload-file *", "*-d *", "*--data *", "*-F *") by Processes.action @@ -83,8 +84,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_file_download_via_certutil.yml b/detections/endpoint/windows_file_download_via_certutil.yml index ae8b5b588f..cb33322586 100644 --- a/detections/endpoint/windows_file_download_via_certutil.yml +++ b/detections/endpoint/windows_file_download_via_certutil.yml @@ -1,7 +1,7 @@ name: Windows File Download Via CertUtil id: 7fac8d40-e370-45ea-a4a3-031bbcc18b02 -version: 2 -date: '2025-05-02' +version: 3 +date: '2025-06-30' author: Nasreddine Bencherchali, Michael Haag, Splunk status: production type: TTP @@ -10,6 +10,7 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where `process_certutil` AND ((Processes.process IN ("*-URL *", "*/URL *")) OR (Processes.process IN ("*urlcache*", "*verifyctl*") AND Processes.process IN ("*/f *", "*-f *"))) by Processes.action Processes.dest @@ -88,9 +89,14 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_file_download_via_powershell.yml b/detections/endpoint/windows_file_download_via_powershell.yml new file mode 100644 index 0000000000..223d752a59 --- /dev/null +++ b/detections/endpoint/windows_file_download_via_powershell.yml @@ -0,0 +1,121 @@ +name: Windows File Download Via PowerShell +id: 58c4e56c-b5b8-46a3-b5fb-6537dca3c6de +version: 1 +date: '2025-06-23' +author: Michael Haag, Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + The following analytic detects the use of PowerShell's download methods such as + "DownloadString" and "DownloadData" from the WebClient class or Invoke-WebRequest + and it's aliases "IWR" or "Curl". + It leverages data from Endpoint Detection and Response (EDR) agents, focusing on + process execution logs that include command-line details. + This activity can be significant such methods and functions are commonly used in malicious + PowerShell scripts to fetch and execute remote code. + If confirmed malicious, this behavior could allow an attacker to download and run + arbitrary code, potentially leading to unauthorized access, data exfiltration, + or further compromise of the affected system. +data_source: +- Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_powershell` + Processes.process IN ( + "*iwr *", "*Invoke-WebRequest*", "*wget *", + "curl", "*.DownloadData*", "*.DownloadFile*", + "*.DownloadString*" + ) + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec + Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_file_download_via_powershell_filter`' +how_to_implement: | + The detection is based on data that originates from Endpoint Detection + and Response (EDR) agents. These agents are designed to provide security-related + telemetry from the endpoints where the agent is installed. To implement this search, + you must ingest logs that contain the process GUID, process name, and parent process. + Additionally, you must ingest complete command-line executions. These logs must + be processed using the appropriate Splunk Technology Add-ons that are specific to + the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` + data model. Use the Splunk Common Information Model (CIM) to normalize the field + names and speed up the data modeling process. +known_false_positives: | + False positives may be present and filtering will need to occur + by parent process or command line argument. It may be required to modify this query + to an EDR product for more granular coverage. +references: +- https://learn.microsoft.com/en-us/dotnet/api/system.net.webclient?view=net-9.0#methods +- https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md +- https://thedfirreport.com/2023/05/22/icedid-macro-ends-in-nokoyawa-ransomware/ +drilldown_searches: +- name: View the detection results for - "$user$" and "$dest$" + search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$user$" and "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: File download activity initiated on $dest$ by user $user$. + $process_name$ was identified calling a download function $process$ + risk_objects: + - field: user + type: user + score: 56 + - field: dest + type: system + score: 56 + threat_objects: + - field: parent_process_name + type: parent_process_name + - field: process_name + type: process_name +tags: + analytic_story: + - Winter Vivern + - Phemedrone Stealer + - Malicious PowerShell + - Data Destruction + - SysAid On-Prem Software CVE-2023-47246 Vulnerability + - PHP-CGI RCE Attack on Japanese Organizations + - Hermetic Wiper + - IcedID + - Ingress Tool Transfer + - HAFNIUM Group + - XWorm + asset_type: Endpoint + mitre_attack_id: + - T1059.001 + - T1105 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + security_domain: endpoint +tests: +- name: True Positive Test - Sysmon + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml index 41565e5f23..65f7440c8c 100644 --- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml +++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml @@ -1,7 +1,7 @@ name: Windows HTTP Network Communication From MSIExec id: b0fd38c7-f71a-43a2-870e-f3ca06bcdd99 -version: 5 -date: '2025-05-02' +version: 6 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: Anomaly @@ -16,6 +16,7 @@ description: or further malware deployment. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where `process_msiexec` by _time Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid @@ -89,8 +90,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: - - name: True Positive Test + - name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index 7cd6f2a39c..2c612e5a66 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -1,10 +1,10 @@ name: Windows InstallUtil Remote Network Connection id: 4fbf9270-43da-11ec-9486-acde48001122 -version: 14 -date: '2025-05-02' +version: 15 +date: '2025-06-26' author: Michael Haag, Splunk status: production -type: TTP +type: Anomaly description: The following analytic detects the Windows InstallUtil.exe binary making a remote network connection. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and network telemetry. This activity is significant @@ -16,9 +16,12 @@ description: The following analytic detects the Windows InstallUtil.exe binary m of this activity. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 -search: |- +- Cisco Network Visibility Module Flow Data +search: | | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - where `process_installutil` by _time span=1h Processes.action Processes.dest Processes.original_file_name + where `process_installutil` + by _time span=1h + Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash @@ -29,8 +32,9 @@ search: |- | `security_content_ctime(lastTime)` | join process_id dest [| tstats `security_content_summariesonly` - count FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != - 0 by All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in All_Traffic.bytes_out + count FROM datamodel=Network_Traffic.All_Traffic where + All_Traffic.dest_port != 0 + by All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in All_Traffic.bytes_out All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.dvc All_Traffic.protocol All_Traffic.protocol_version All_Traffic.src All_Traffic.src_ip All_Traffic.src_port All_Traffic.transport All_Traffic.user All_Traffic.vendor_product All_Traffic.direction All_Traffic.process_id @@ -38,9 +42,14 @@ search: |- | rename dest as command_and_control | rename src as dest] | table _time user src dest parent_process_name process_name process_path process process_id dest_port command_and_control - | stats count min(_time) as firstTime max(_time) as lastTime values(process) as process values(command_and_control) as command_and_control by user dest process_name process_id dest_port parent_process_name + | stats count min(_time) as firstTime + max(_time) as lastTime + values(process) as process + values(command_and_control) as command_and_control + by user dest process_name process_id dest_port parent_process_name | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)`| `windows_installutil_remote_network_connection_filter` + | `security_content_ctime(lastTime)` + | `windows_installutil_remote_network_connection_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -98,8 +107,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 9681700f1c..8f8bc7d20e 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil URL in Command Line id: 28e06670-43df-11ec-a569-acde48001122 -version: 10 -date: '2025-05-02' +version: 11 +date: '2025-02-03' author: Michael Haag, Splunk status: production type: TTP @@ -17,15 +17,21 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_installutil` Processes.process - IN ("*http://*","*https://*") by Processes.action Processes.dest Processes.original_file_name +- Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_installutil` + Processes.process IN ("*http://*","*https://*") + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_installutil_url_in_command_line_filter`' + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_installutil_url_in_command_line_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -84,8 +90,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.004/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index c4a17e03c1..81e84388cf 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -1,11 +1,11 @@ name: Windows MSIExec Remote Download id: 6aa49ff2-3c92-4586-83e0-d83eb693dfda -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-06-26' author: Michael Haag, Splunk status: production type: TTP -description: +description: | The following analytic detects the use of msiexec.exe with an HTTP or HTTPS URL in the command line, indicating a remote file download attempt. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process @@ -17,17 +17,22 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: - '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_msiexec` Processes.process - IN ("*http://*", "*https://*") by Processes.action Processes.dest Processes.original_file_name + - Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_msiexec` + Processes.process IN ("*http://*", "*https://*") + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_msiexec_remote_download_filter`' -how_to_implement: + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_msiexec_remote_download_filter` +how_to_implement: | The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, @@ -37,9 +42,8 @@ how_to_implement: the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: - False positives may be present, filter by destination or parent - process as needed. +known_false_positives: | + False positives may be present, filter by destination or parent process as needed. references: - https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/ - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.007/T1218.007.md @@ -87,8 +91,13 @@ tags: - Splunk Cloud security_domain: endpoint tests: - - name: True Positive Test + - name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.007/atomic_red_team/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml index 4154d3cde1..a40e4cd4ac 100644 --- a/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml +++ b/detections/endpoint/windows_office_product_spawned_child_process_for_download.yml @@ -1,7 +1,7 @@ name: Windows Office Product Spawned Child Process For Download id: f02b64b8-cbea-4f75-bf77-7a05111566b1 -version: 4 -date: '2025-05-02' +version: 5 +date: '2025-06-26' author: Teoderick Contreras, Splunk status: production type: TTP @@ -17,17 +17,26 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_office_products_parent` - Processes.process IN ("*http:*","*https:*") NOT (Processes.original_file_name IN - ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe")) by Processes.action Processes.dest +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_office_products_parent` + Processes.process IN ("*http:*","*https:*") + NOT ( + Processes.original_file_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe") + OR + Processes.process_name IN ("firefox.exe", "chrome.exe","iexplore.exe","msedge.exe") + ) + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_office_product_spawned_child_process_for_download_filter`' + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_office_product_spawned_child_process_for_download_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, diff --git a/lookups/attacker_tools.csv b/lookups/attacker_tools.csv index c7a5bf78b8..dcad4d40c7 100644 --- a/lookups/attacker_tools.csv +++ b/lookups/attacker_tools.csv @@ -1,38 +1,35 @@ attacker_tool_names,description -remcom.exe,This process is an open source replacement to psexec and is not typically seen in an enterprise environment. -pwdump.exe,This process is associated with a tool used to dump password hashes on a Windows system. -pwdump2.exe,This process is associated with a tool used to dump password hashes on a Windows system. -nc.exe,This process is an open source tool used for network communications. -wce.exe,This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks. +advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports. cain.exe,This process is associated with a tool used to collect user credentials and execute attacks. -nmap.exe,This process is an open source network mapping tool used to identify hosts and listening services on a network. -kidlogger.exe,This process is associated with a tool used to collect keyboard input on a host. -isass.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. -svch0st.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. -at.exe,This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility. +certify.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) +certipy.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) +fscan.exe,Fscan is a tool used to scan for open ports and services on a network. getmail.exe,This process is seen to be used by attackers to extract email files from host machines. -ntdll.exe,This process was identified as malicious by DHS Alert TA18-074A. -netpass.exe,This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user. -WebBrowserPassView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers. -OutlookAddressBookView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook. +isass.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. +kidlogger.exe,This process is associated with a tool used to collect keyboard input on a host. +KPortScan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks. mailpv.exe,This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients. -NLBrute.exe,A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords. -selfdel.exe,This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities. masscan.exe,This executable was delivered in the XMRig Crypto Miner Massscan_GUI.exe,This executable was delivered in the XMRig Crypto Miner -KPortScan3.exe,This executable was delivered in the XMRig Crypto Miner and is commonly used by attackers to scan the internet +mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets. +nc.exe,This process is an open source tool used for network communications. +netpass.exe,This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user. NLAChecker.exe,A scanner tool that checks for Windows hosts for Network Level Authentication. This tool allows attackers to detect Windows Servers with RDP without NLA enabled which facilitates the use of brute force non microsoft rdp tools or exploits +NLBrute.exe,A RDP brute force tool found in botnets for further expansion and and acquisition of targets. This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords. +nmap.exe,This process is an open source network mapping tool used to identify hosts and listening services on a network. ns.exe,A commonly used tool used by attackers to scan and map file shares -SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts. -kportscan3.exe, KPortScan 3.0 is a widely used port scanning tool on Hacking Forums to perform network scanning on the internal networks. -advanced_port_scanner.exe,Advanced Port Scanner is a free network scanner allowing you to quickly find open ports on network computers and retrieve versions of programs running on the detected ports. -mimikatz.exe,utility Mimikatz is an open-source application that allows users to view and save authentication credentials such as Kerberos tickets. -certify.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) -certipy.exe,A tool used to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS) -ladon.exe,Ladon is a multi-threaded plug-in comprehensive scanning artifact for large-scale network penetration including port scanning service identification network assets password explosion high-risk vulnerability detection and one click getshell. -sharpTask.exe,SharpTask is a tool that allows you to create scheduled tasks on a Windows system. -SharpHide.exe,SharpHide is a tool that allows you to hide a process from the task manager. -SharpStay.exe,SharpStay is a tool that allows you to stay hidden from the task manager. +ntdll.exe,This process was identified as malicious by DHS Alert TA18-074A. +OutlookAddressBookView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook. +pwdump.exe,This process is associated with a tool used to dump password hashes on a Windows system. +pwdump2.exe,This process is associated with a tool used to dump password hashes on a Windows system. +remcom.exe,This process is an open source replacement to psexec and is not typically seen in an enterprise environment. seatbelt.exe,A tool used to collect detailed information about a system—such as remote access configurations network shares and other security-relevant data on victim machine. +selfdel.exe,This executable was delivered in the SamSam Ransomware Campaign and the attackers leveraged this binary to delete its malicious activities. SharpGPOAbuse.exe,SharpGPOAbuse is a tool that allows you to abuse and enumerate GPOs on a Windows system. -fscan.exe,Fscan is a tool used to scan for open ports and services on a network. \ No newline at end of file +SharpHide.exe,SharpHide is a tool that allows you to hide a process from the task manager. +SharpStay.exe,SharpStay is a tool that allows you to stay hidden from the task manager. +sharpTask.exe,SharpTask is a tool that allows you to create scheduled tasks on a Windows system. +SilverBullet.exe,Malware was discovered in our monitoring of honey pots that abuses this open source software for scanning and connecting to hosts. +svch0st.exe,This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. +wce.exe,This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks. +WebBrowserPassView.exe,This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers. diff --git a/lookups/attacker_tools.yml b/lookups/attacker_tools.yml index dfbe78b94e..ede9b5d417 100644 --- a/lookups/attacker_tools.yml +++ b/lookups/attacker_tools.yml @@ -1,6 +1,6 @@ name: attacker_tools -date: 2025-03-18 -version: 3 +date: 2025-06-23 +version: 4 id: 72620fe1-26cb-4cee-a6ee-8c6127056d81 author: Splunk Threat Research Team lookup_type: csv @@ -8,4 +8,4 @@ description: A list of tools used by attackers match_type: - WILDCARD(attacker_tool_names) min_matches: 1 -case_sensitive_match: false \ No newline at end of file +case_sensitive_match: false diff --git a/removed/deprecation_mapping.YML b/removed/deprecation_mapping.YML index 76db545adf..783e93e3bf 100644 --- a/removed/deprecation_mapping.YML +++ b/removed/deprecation_mapping.YML @@ -1,4 +1,19 @@ detections: + - content: Windows InstallUtil Uninstall Option with Network + removed_in_version: 5.11.0 + reason: Detection has been deprecated as its scope is already covered by "Windows InstallUtil Remote Network Connection". + replacement_content: + - Windows InstallUtil Remote Network Connection + - content: Any Powershell DownloadString + removed_in_version: 5.11.0 + reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management. + replacement_content: + - Windows File Download Via PowerShell + - content: Any Powershell DownloadFile + removed_in_version: 5.11.0 + reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management. + replacement_content: + - Windows File Download Via PowerShell - content: Windows AD Suspicious GPO Modification removed_in_version: 5.10.0 reason: Detection deprecated due to lack of data and consistency. Research is being done to create potential replacement in a future release. From 52d97d3207813d468de991e020425acc956b6b86 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 30 Jun 2025 14:01:14 +0200 Subject: [PATCH 02/21] rename datasrouce files --- ...low_data.yml => cisco_network_visibility_module_flow_data.yml} | 0 ...or_osquery.yml => cisco_network_visibility_module_osquery.yml} | 0 2 files changed, 0 insertions(+), 0 deletions(-) rename data_sources/{cisco_network_visibility_monitor_flow_data.yml => cisco_network_visibility_module_flow_data.yml} (100%) rename data_sources/{cisco_network_visibility_monitor_osquery.yml => cisco_network_visibility_module_osquery.yml} (100%) diff --git a/data_sources/cisco_network_visibility_monitor_flow_data.yml b/data_sources/cisco_network_visibility_module_flow_data.yml similarity index 100% rename from data_sources/cisco_network_visibility_monitor_flow_data.yml rename to data_sources/cisco_network_visibility_module_flow_data.yml diff --git a/data_sources/cisco_network_visibility_monitor_osquery.yml b/data_sources/cisco_network_visibility_module_osquery.yml similarity index 100% rename from data_sources/cisco_network_visibility_monitor_osquery.yml rename to data_sources/cisco_network_visibility_module_osquery.yml From c36a2668cb3c4065457aa60767655a4f1cd3835a Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 30 Jun 2025 14:30:26 +0200 Subject: [PATCH 03/21] update dataset url --- detections/endpoint/attacker_tools_on_endpoint.yml | 2 +- detections/endpoint/detect_html_help_url_in_command_line.yml | 2 +- detections/endpoint/detect_mshta_url_in_command_line.yml | 2 +- .../endpoint/windows_curl_download_to_suspicious_path.yml | 2 +- .../endpoint/windows_curl_upload_to_remote_destination.yml | 2 +- detections/endpoint/windows_file_download_via_certutil.yml | 2 +- detections/endpoint/windows_file_download_via_powershell.yml | 2 +- .../windows_http_network_communication_from_msiexec.yml | 2 +- .../endpoint/windows_installutil_remote_network_connection.yml | 2 +- detections/endpoint/windows_installutil_url_in_command_line.yml | 2 +- detections/endpoint/windows_msiexec_remote_download.yml | 2 +- 11 files changed, 11 insertions(+), 11 deletions(-) diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index c8b5d61cff..06dd576973 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -95,6 +95,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 56e9278994..84629d7a62 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -95,6 +95,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 70a2978c99..567c4ef8b0 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -97,6 +97,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index aeaf1addd1..6eea9f0c8f 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -97,6 +97,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index dd512af657..9566a780b4 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -91,6 +91,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_file_download_via_certutil.yml b/detections/endpoint/windows_file_download_via_certutil.yml index cb33322586..3c5122dc8b 100644 --- a/detections/endpoint/windows_file_download_via_certutil.yml +++ b/detections/endpoint/windows_file_download_via_certutil.yml @@ -97,6 +97,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_file_download_via_powershell.yml b/detections/endpoint/windows_file_download_via_powershell.yml index 223d752a59..197522d8c7 100644 --- a/detections/endpoint/windows_file_download_via_powershell.yml +++ b/detections/endpoint/windows_file_download_via_powershell.yml @@ -116,6 +116,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml index 65f7440c8c..571bdd6e06 100644 --- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml +++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml @@ -97,6 +97,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index 2c612e5a66..fb46654ef3 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -114,6 +114,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index 8f8bc7d20e..e358e2abaf 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -97,6 +97,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index 81e84388cf..e092b94504 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -98,6 +98,6 @@ tests: sourcetype: XmlWinEventLog - name: True Positive Test - Cisco NVM attack_data: - - data: https://github.com/splunk/attack_data/blob/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log source: not_applicable sourcetype: cisco:nvm:flowdata From d66b88d2ff0807bd46c824b753a31db1418b3400 Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Mon, 30 Jun 2025 12:26:52 -0400 Subject: [PATCH 04/21] add new ta-cisco-nvm app to support new detections --- contentctl.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/contentctl.yml b/contentctl.yml index 93b8e006a4..76aba8c5ee 100644 --- a/contentctl.yml +++ b/contentctl.yml @@ -225,4 +225,12 @@ apps: description: The Splunk Add-on for AppDynamics enables you to easily configure data inputs to pull data from AppDynamics' REST APIs hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_314.tgz +- uid: 4221 + title: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk + appid: TA-Cisco-NVM + version: 4.0.7 + description: The Cisco Endpoint Security Analytics (CESA) Add-On for Splunk allows IT administrators to analyze and correlate user and endpoint behavior in Splunk Enterprise. + This Add-on provides configuration and collection of data from the Cisco AnyConnect Network Visibility Module IPFIX (nvzFlow) Collector. + This module collects additional context such as user, device, application, location and destination for flows both on and off premise. + hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-endpoint-security-analytics-cesa-add-on-for-splunk_407.tgz githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd From 1601ff777a60bde30907aae08cb8e2f07937c8cb Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 30 Jun 2025 23:41:42 +0200 Subject: [PATCH 05/21] small updates --- ...co_network_visibility_module_flow_data.yml | 2 +- ...isco_network_visibility_module_osquery.yml | 4 +- ...no_command_line_arguments_with_network.yml | 68 ++++++++++++------- ...rshell_fakecaptcha_clipboard_execution.yml | 17 +++-- 4 files changed, 58 insertions(+), 33 deletions(-) diff --git a/data_sources/cisco_network_visibility_module_flow_data.yml b/data_sources/cisco_network_visibility_module_flow_data.yml index 819533b02d..912d292de3 100644 --- a/data_sources/cisco_network_visibility_module_flow_data.yml +++ b/data_sources/cisco_network_visibility_module_flow_data.yml @@ -7,7 +7,7 @@ description: Data source object for Netflow events from Cisco Network Visibility source: not_applicable sourcetype: cisco:nvm:flowdata supported_TA: -- name: Cisco Security Cloud +- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk url: https://splunkbase.splunk.com/app/4221 version: 4.0.7 fields: diff --git a/data_sources/cisco_network_visibility_module_osquery.yml b/data_sources/cisco_network_visibility_module_osquery.yml index 098daf00a7..8bc2be6846 100644 --- a/data_sources/cisco_network_visibility_module_osquery.yml +++ b/data_sources/cisco_network_visibility_module_osquery.yml @@ -7,7 +7,7 @@ description: Data source object for OSquery events from Cisco Network Visibility source: not_applicable sourcetype: cisco:nvm:osquery supported_TA: -- name: Cisco Security Cloud +- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk url: https://splunkbase.splunk.com/app/4221 version: 4.0.7 fields: @@ -48,4 +48,4 @@ fields: - udid output_fields: - query_json_response -example_log: 'Jun 30 09:20:43 127.0.0.1 Jun 30 09:20:43 ip-172-31-30-201 fv="nvzFlow_v8" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" qv="5.5.1-dirty" qid="38654705666" qt="1751275242" qpi="1" qpn="1" qjr="[{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"addons-search-detection@mozilla.com\",\"location\":\"app-builtin\",\"name\":\"Add-ons Search Detection\",\"native\":\"\",\"path\":\"null\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.0.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Mozilla \",\"description\":\"Take clips and screenshots from the Web and save them temporarily or permanently.\",\"disabled\":\"1\",\"identifier\":\"screenshots@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Firefox Screenshots\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\screenshots@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"39.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"formautofill@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Form Autofill\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\formautofill@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Fixes for web compatibility with Picture-in-Picture\",\"disabled\":\"0\",\"identifier\":\"pictureinpicture@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Picture-In-Picture\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\pictureinpicture@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.0\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Urgent post-release fixes for web compatibility.\",\"disabled\":\"0\",\"identifier\":\"webcompat@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Web Compatibility Interventions\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"137.7.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Thomas Wisniewski \",\"description\":\"Report site compatibility issues on webcompat.com\",\"disabled\":\"1\",\"identifier\":\"webcompat-reporter@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"WebCompat Reporter\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat-reporter@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.1.0\",\"visible\":\"1\"}]"' \ No newline at end of file +example_log: 'Jun 30 09:20:43 127.0.0.1 Jun 30 09:20:43 ip-172-31-30-201 fv="nvzFlow_v8" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" qv="5.5.1-dirty" qid="38654705666" qt="1751275242" qpi="1" qpn="1" qjr="[{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"addons-search-detection@mozilla.com\",\"location\":\"app-builtin\",\"name\":\"Add-ons Search Detection\",\"native\":\"\",\"path\":\"null\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.0.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Mozilla \",\"description\":\"Take clips and screenshots from the Web and save them temporarily or permanently.\",\"disabled\":\"1\",\"identifier\":\"screenshots@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Firefox Screenshots\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\screenshots@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"39.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"formautofill@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Form Autofill\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\formautofill@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Fixes for web compatibility with Picture-in-Picture\",\"disabled\":\"0\",\"identifier\":\"pictureinpicture@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Picture-In-Picture\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\pictureinpicture@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.0\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Urgent post-release fixes for web compatibility.\",\"disabled\":\"0\",\"identifier\":\"webcompat@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Web Compatibility Interventions\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"137.7.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Thomas Wisniewski \",\"description\":\"Report site compatibility issues on webcompat.com\",\"disabled\":\"1\",\"identifier\":\"webcompat-reporter@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"WebCompat Reporter\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat-reporter@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.1.0\",\"visible\":\"1\"}]"' diff --git a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml index 4362461f14..c52cb0ddf9 100644 --- a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml @@ -1,41 +1,56 @@ name: DLLHost with no Command Line Arguments with Network id: f1c07594-a141-11eb-8407-acde48001122 -version: 12 -date: '2025-06-10' +version: 13 +date: '2025-06-30' author: Steven Dick, Michael Haag, Splunk status: production type: TTP -description: The following analytic detects instances of DLLHost.exe running without - command line arguments while establishing a network connection. This behavior is - identified using Endpoint Detection and Response (EDR) telemetry, focusing on process - execution and network activity data. It is significant because DLLHost.exe typically - runs with specific arguments, and its absence can indicate malicious activity, such - as Cobalt Strike usage. If confirmed malicious, this activity could allow attackers - to execute code, move laterally, or exfiltrate data, posing a severe threat to the - network's security. +description: | + The following analytic detects instances of DLLHost.exe running without + command line arguments while establishing a network connection. + This behavior is identified using Endpoint Detection and Response (EDR) telemetry, + focusing on process execution and network activity data. + It is significant because DLLHost.exe typically runs with specific arguments, + and its absence can indicate malicious activity, such as Cobalt Strike usage. + If confirmed malicious, this activity could allow attackers to execute code, + move laterally, or exfiltrate data, posing a severe threat to the network's security. data_source: - Sysmon EventID 1 AND Sysmon EventID 3 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=dllhost.exe - Processes.action!="blocked" by host _time span=1h +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime FROM datamodel=Endpoint.Processes where + Processes.process_name=dllhost.exe + Processes.action!="blocked" + by host _time span=1h Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | regex process="(?i)(dllhost\.exe.{0,4}$)" - | rename dest as src | join host process_id [| tstats `security_content_summariesonly` - count latest(All_Traffic.dest) as dest latest(All_Traffic.dest_ip) as dest_ip latest(All_Traffic.dest_port) - as dest_port FROM datamodel=Network_Traffic.All_Traffic where All_Traffic.dest_port != 0 - by host All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in All_Traffic.bytes_out - All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.dvc All_Traffic.protocol - All_Traffic.protocol_version All_Traffic.src All_Traffic.src_ip All_Traffic.src_port - All_Traffic.transport All_Traffic.user All_Traffic.vendor_product All_Traffic.direction - All_Traffic.process_id - | `drop_dm_object_name(All_Traffic)`] | `dllhost_with_no_command_line_arguments_with_network_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | regex process="(?i)(dllhost\.exe.{0,4}$)" + | rename dest as src + | join host process_id [ + | tstats `security_content_summariesonly` + count + latest(All_Traffic.dest) as dest + latest(All_Traffic.dest_ip) as dest_ip + latest(All_Traffic.dest_port) as dest_port + FROM datamodel=Network_Traffic.All_Traffic where + All_Traffic.dest_port != 0 + by host All_Traffic.action All_Traffic.app All_Traffic.bytes All_Traffic.bytes_in + All_Traffic.bytes_out All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port + All_Traffic.dvc All_Traffic.protocol All_Traffic.protocol_version All_Traffic.src + All_Traffic.src_ip All_Traffic.src_port All_Traffic.transport All_Traffic.user + All_Traffic.vendor_product All_Traffic.direction All_Traffic.process_id + | `drop_dm_object_name(All_Traffic)` + ] + | `dllhost_with_no_command_line_arguments_with_network_filter` +how_to_implement: | + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. @@ -44,7 +59,8 @@ how_to_implement: The detection is based on data that originates from Endpoint D the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: Although unlikely, some legitimate third party applications +known_false_positives: | + Although unlikely, some legitimate third party applications may use a moved copy of dllhost, triggering a false positive. references: - https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile diff --git a/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml b/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml index 32be656d9a..c58a7a3318 100644 --- a/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml +++ b/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml @@ -1,13 +1,17 @@ name: Windows PowerShell FakeCAPTCHA Clipboard Execution id: d81d4d3d-76b5-4f21-ab51-b17d5164c106 -version: 1 -date: '2025-05-14' +version: 2 +date: '2025-06-30' author: Michael Haag, Splunk status: production type: TTP -description: This detection identifies potential FakeCAPTCHA/ClickFix clipboard hijacking campaigns by looking for PowerShell execution with hidden window parameters and distinctive strings related to fake CAPTCHA verification. These campaigns use social engineering to trick users into pasting malicious PowerShell commands from their clipboard, typically delivering information stealers or remote access trojans. +description: | + This detection identifies potential FakeCAPTCHA/ClickFix clipboard hijacking campaigns by looking for PowerShell execution with hidden window parameters and distinctive strings related to fake CAPTCHA verification. These campaigns use social engineering to trick users into pasting malicious PowerShell commands from their clipboard, typically delivering information stealers or remote access trojans. data_source: - Sysmon EventID 1 +- Windows Event Log Security 4688 +- CrowdStrike ProcessRollup2 +- Cisco Network Visibility Module Flow Data search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where `process_powershell` AND Processes.process="*-w*h*" @@ -84,8 +88,13 @@ tags: security_domain: endpoint cve: [] tests: -- name: True Positive Test +- name: True Positive Test - Sysmon attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/captcha_windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog +- name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata From 75ec47e99a1efde613d379788d87c97640285294 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Tue, 1 Jul 2025 23:04:48 +0200 Subject: [PATCH 06/21] add new detections, story and other cool things --- .../endpoint/attacker_tools_on_endpoint.yml | 1 + ...its_download_from_file_sharing_website.yml | 97 +++++++++++++++++++ ...outbound_connection_to_suspicious_port.yml | 96 ++++++++++++++++++ .../detect_html_help_url_in_command_line.yml | 1 + .../detect_mshta_url_in_command_line.yml | 1 + ...ndows_curl_download_to_suspicious_path.yml | 1 + ...dows_curl_upload_to_remote_destination.yml | 1 + .../windows_file_download_via_certutil.yml | 1 + .../windows_file_download_via_powershell.yml | 1 + ...ttp_network_communication_from_msiexec.yml | 1 + ...s_ingress_tool_transfer_using_explorer.yml | 12 ++- ..._installutil_remote_network_connection.yml | 1 + ...indows_installutil_url_in_command_line.yml | 1 + .../windows_msiexec_remote_download.yml | 1 + ...rshell_fakecaptcha_clipboard_execution.yml | 1 + ..._firewall___repeated_malware_downloads.yml | 2 +- lookups/suspicious_ports_list.csv | 86 ++++++++++++++++ lookups/suspicious_ports_list.yml | 11 +++ ...sco_network_visibility_module_flowdata.yml | 3 + ...co_network_visibility_module_analytics.yml | 27 ++++++ 20 files changed, 340 insertions(+), 6 deletions(-) create mode 100644 detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml create mode 100644 detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml create mode 100644 lookups/suspicious_ports_list.csv create mode 100644 lookups/suspicious_ports_list.yml create mode 100644 macros/cisco_network_visibility_module_flowdata.yml create mode 100644 stories/cisco_network_visibility_module_analytics.yml diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 06dd576973..af9707b19f 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -77,6 +77,7 @@ tags: - CISA AA22-264A - Compromised Windows Host - PHP-CGI RCE Attack on Japanese Organizations + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1003 diff --git a/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml new file mode 100644 index 0000000000..f158c19588 --- /dev/null +++ b/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml @@ -0,0 +1,97 @@ +name: Cisco NVM - BITS Download From File Sharing Website +id: 94ebc001-35e7-4ae8-9b0e-52766b2f99c7 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + The following analytic detects a network connection flow from the BITS service towards a file sharing website. + It leverages Cisco Network Visibility Module logs, specifically flow data logs. + The BITS service communicating to these domains might indicate an activity where the user is leveraging bitsadmin + or its COM object to in order to download suspicious files. + If confirmed malicious, this behavior could indicate an active infection or on keyboard activity. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "svchost.exe" + process_arguments = "*-s BITS*" + dest_hostname IN ( + "*.githubusercontent.com*", "*anonfiles.com*", "*cdn.discordapp.com*", "*ddns.net*", + "*dl.dropboxusercontent.com*", "*ghostbin.co*", "*glitch.me*", "*gofile.io*", + "*hastebin.com*", "*mediafire.com*", "*mega.nz*", "*onrender.com*", "*pages.dev*", + "*paste.ee*", "*pastebin.com*", "*pastebin.pl*", "*pastetext.net*", "*privatlab.com*", + "*privatlab.net*", "*send.exploit.in*", "*sendspace.com*", "*storage.googleapis.com*", + "*storjshare.io*", "*supabase.co*", "*temp.sh*", "*transfer.sh*", "*trycloudflare.com*", + "*ufile.io*", "*w3spaces.com*", "*workers.dev*" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + by src dest parent_process_path parent_process_integrity_level parent_process_id process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash parent_process_id + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest dest_port transport firstTime lastTime + | `cisco_nvm___bits_download_from_file_sharing_website_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + False positives should be minimal, as the list of domains is suspicious. If for whatever reason you make use of bitsadmin or its COM objects to download files over these domains legitimately. Apply additional filters by modifying the filter macro. +references: + - https://twitter.com/jhencinski/status/1102695118455349248 + - https://isc.sans.edu/forums/diary/Investigating+Microsoft+BITS+Activity/23281/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ used BITS service to communicate and potentially download files from $dest_hostname$ over $dest_port$ + risk_objects: + - field: src + type: system + score: 30 + threat_objects: + - field: dest_hostname + type: other +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1197 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml new file mode 100644 index 0000000000..d6d14d98c3 --- /dev/null +++ b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml @@ -0,0 +1,96 @@ +name: Cisco NVM - Outbound Connection to Suspicious Port +id: fc32a8d5-bc79-4437-b48f-4646ab7bed9d +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + The following analytic detects any outbound network connection from an endpoint process to a known suspicious or non-standard port. + It leverages Cisco Network Visibility Module flow data logs to identify potentially suspicious behavior by looking at processes + communicating over ports like 4444, 2222, or 51820 are commonly used by tools like Metasploit, SliverC2 or other pentest, red team or malware. + These connections are worth investigating further, especially when initiated by unexpected or non-network-native binaries. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + by src dest parent_process_path parent_process_integrity_level parent_process_id process_path process_integrity_level process_id transport + | lookup suspicious_ports_list dest_port OUTPUTNEW comment as dest_port_metadata confidence as dest_confidence category as dest_port_category + | where isnotnull(dest_port_metadata) + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash parent_process_id + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest dest_port dest_port_category transport dest_port_metadata dest_port_confidence + firstTime lastTime + | `cisco_nvm___outbound_connection_to_suspicious_port` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some legitimate applications may use high or non-standard ports, such as alternate SSH daemons or development tools. + However, many of these ports are commonly used by threat actors for reverse shells or C2 communications. + Review the associated process and command-line context to determine intent. +references: + - https://mthcht.medium.com/hunting-for-suspicious-ports-activities-50ef56d5cef +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ established an outbound network connection via the process $process_path$ with the commandline arguments $process_arguments$ to $dest$ over suspicious port $dest_port$. + risk_objects: + - field: dest + type: system + score: 30 + threat_objects: + - field: process_path + type: process +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1571 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_html_help_url_in_command_line.yml b/detections/endpoint/detect_html_help_url_in_command_line.yml index 84629d7a62..6b8d49e5ff 100644 --- a/detections/endpoint/detect_html_help_url_in_command_line.yml +++ b/detections/endpoint/detect_html_help_url_in_command_line.yml @@ -79,6 +79,7 @@ tags: - Suspicious Compiled HTML Activity - Living Off The Land - Compromised Windows Host + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.001 diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index 567c4ef8b0..a5e586d3da 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -81,6 +81,7 @@ tags: - Living Off The Land - Suspicious MSHTA Activity - XWorm + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.005 diff --git a/detections/endpoint/windows_curl_download_to_suspicious_path.yml b/detections/endpoint/windows_curl_download_to_suspicious_path.yml index 6eea9f0c8f..a1cfe2a3ad 100644 --- a/detections/endpoint/windows_curl_download_to_suspicious_path.yml +++ b/detections/endpoint/windows_curl_download_to_suspicious_path.yml @@ -81,6 +81,7 @@ tags: - Salt Typhoon - Ingress Tool Transfer - IcedID + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1105 diff --git a/detections/endpoint/windows_curl_upload_to_remote_destination.yml b/detections/endpoint/windows_curl_upload_to_remote_destination.yml index 9566a780b4..fc2336e6a9 100644 --- a/detections/endpoint/windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/windows_curl_upload_to_remote_destination.yml @@ -75,6 +75,7 @@ tags: analytic_story: - Compromised Windows Host - Ingress Tool Transfer + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1105 diff --git a/detections/endpoint/windows_file_download_via_certutil.yml b/detections/endpoint/windows_file_download_via_certutil.yml index 3c5122dc8b..954837a167 100644 --- a/detections/endpoint/windows_file_download_via_certutil.yml +++ b/detections/endpoint/windows_file_download_via_certutil.yml @@ -80,6 +80,7 @@ tags: - Flax Typhoon - Compromised Windows Host - CISA AA22-277A + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1105 diff --git a/detections/endpoint/windows_file_download_via_powershell.yml b/detections/endpoint/windows_file_download_via_powershell.yml index 197522d8c7..f3b955ca23 100644 --- a/detections/endpoint/windows_file_download_via_powershell.yml +++ b/detections/endpoint/windows_file_download_via_powershell.yml @@ -99,6 +99,7 @@ tags: - Ingress Tool Transfer - HAFNIUM Group - XWorm + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1059.001 diff --git a/detections/endpoint/windows_http_network_communication_from_msiexec.yml b/detections/endpoint/windows_http_network_communication_from_msiexec.yml index 571bdd6e06..168a65c311 100644 --- a/detections/endpoint/windows_http_network_communication_from_msiexec.yml +++ b/detections/endpoint/windows_http_network_communication_from_msiexec.yml @@ -81,6 +81,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec - Water Gamayun + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.007 diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml index 7bf3fc26cb..63b368136e 100644 --- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml +++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml @@ -17,17 +17,19 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = explorer.exe - OR Processes.original_file_name = explorer.exe) AND NOT (Processes.parent_process_name - IN("userinit.exe", "svchost.exe")) Processes.process IN ("* http://*", "* https://*") +search: | + | tstats `security_content_summariesonly` min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + (Processes.process_name = explorer.exe OR Processes.original_file_name = explorer.exe) + AND NOT (Processes.parent_process_name IN("userinit.exe", "svchost.exe")) + Processes.process IN ("* http://*", "* https://*") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `windows_ingress_tool_transfer_using_explorer_filter`' + | `windows_ingress_tool_transfer_using_explorer_filter` how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, diff --git a/detections/endpoint/windows_installutil_remote_network_connection.yml b/detections/endpoint/windows_installutil_remote_network_connection.yml index fb46654ef3..cf57bf4aa5 100644 --- a/detections/endpoint/windows_installutil_remote_network_connection.yml +++ b/detections/endpoint/windows_installutil_remote_network_connection.yml @@ -98,6 +98,7 @@ tags: - Living Off The Land - Compromised Windows Host - Signed Binary Proxy Execution InstallUtil + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.004 diff --git a/detections/endpoint/windows_installutil_url_in_command_line.yml b/detections/endpoint/windows_installutil_url_in_command_line.yml index e358e2abaf..d76d0519e8 100644 --- a/detections/endpoint/windows_installutil_url_in_command_line.yml +++ b/detections/endpoint/windows_installutil_url_in_command_line.yml @@ -81,6 +81,7 @@ tags: - Living Off The Land - Compromised Windows Host - Signed Binary Proxy Execution InstallUtil + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.004 diff --git a/detections/endpoint/windows_msiexec_remote_download.yml b/detections/endpoint/windows_msiexec_remote_download.yml index e092b94504..aab60196f2 100644 --- a/detections/endpoint/windows_msiexec_remote_download.yml +++ b/detections/endpoint/windows_msiexec_remote_download.yml @@ -82,6 +82,7 @@ tags: analytic_story: - Windows System Binary Proxy Execution MSIExec - Water Gamayun + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1218.007 diff --git a/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml b/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml index c58a7a3318..de9a51d6eb 100644 --- a/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml +++ b/detections/endpoint/windows_powershell_fakecaptcha_clipboard_execution.yml @@ -76,6 +76,7 @@ rba: tags: analytic_story: - Fake CAPTCHA Campaigns + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1059.001 diff --git a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml index 849a39dba9..97d2352c2d 100644 --- a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml +++ b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml @@ -6,7 +6,7 @@ author: Nasreddine Bencherchali, Splunk status: production type: Anomaly description: | - The following analytic detects repeated malware file downloads initiated by the same internal host (src_ip) within a short time window. It leverages Cisco Secure Firewall Threat Defense logs and identifies `FileEvent` events with a `SHA_Disposition` of "Malware" and `FileDirection` set to "Download". If ten or more such events occur from the same host within five minutes, this analytic will trigger. This activity may indicate the host is compromised and repeatedly retrieving malicious content—either due to command-and-control, malware staging, or automation. If confirmed malicious, this behavior may represent an infection in progress, persistence mechanism, or a malicious downloader. + The following analytic detects repeated malware file downloads initiated by the same internal host (src_ip) within a short time window. It leverages Cisco Secure Firewall Threat Defense logs and identifies `FileEvent` events with a `SHA_Disposition` of "Malware" and `FileDirection` set to "Download". If ten or more such events occur from the same host within five minutes, this analytic will trigger. This activity may indicate the host is compromised and repeatedly retrieving malicious content either due to command-and-control, malware staging, or automation. If confirmed malicious, this behavior may represent an infection in progress, persistence mechanism, or a malicious downloader. data_source: - Cisco Secure Firewall Threat Defense File Event search: | diff --git a/lookups/suspicious_ports_list.csv b/lookups/suspicious_ports_list.csv new file mode 100644 index 0000000000..71c61ecce3 --- /dev/null +++ b/lookups/suspicious_ports_list.csv @@ -0,0 +1,86 @@ +dest_port,comment,confidence,category +801,manjusaka (cobalstrike chinese clone) default panel ui,medium,malware +1005,Nitedrem trojan Downloader + Pest + Theef,medium,malware +1015,Doly trojan,high,malware +1042,Bla trojan,high,malware +1075,Backdoor.Win32.LanaFTP.k listening on this port,high,malware +1080,Was seen being used by multiple malware, and is also the default port of the pentest utility ligolo,medium,C2 +1170,Psyber Stream Server - PSS,high,malware +1243,SubSeven backdoor,high,malware +1337,Was seen being used by multiple malware and red team or pentest utilities, such as empire, crackmapexec, icebreaker, KittyStager, Cyberghost VPN, gophish, gtunnel. The port is also associated with various other types of exploits or shellcode,high,exploitation +1981,Shockrave malware,high,malware +2001,Millennium Worm and multiple malwares,medium,malware +2773,SubSeven trojan and some backup services,medium,malware +2989,Multiple RAT instances were seen using this port,high,malware +3000,ptunnel-ng + beefproject http panel default port,medium,C2 +3024,WinCrash trojan,high,malware +3030,nuages C2 default port and other malwares,high,C2 +3129,Master's Paradise trojan,high,malware +3200,manjusaka (cobalstrike chinese clone) default panel ui,medium,C2 +3333,gophish + Xmrig coinminer,high,Cryptominer +3410,Optix Pro trojan,high,malware +3790,often used for metasploit but also legit service like quickbooksrds,high,C2 +4000,ptunnel-ng + multiple malwares and RAT but also some legit usages,medium,C2 +4041,Masters Paradise trojan,high,malware +4051,AlanFramework C2 default port but also used by cisco P2P,high,C2 +4092,WinCrash trojan,high,malware +4433,AlanFramework C2 default port and Acidoor backdoor,high,C2 +4444,Default listener port for Metasploit exploits and RemotePC transfer port and gophish,high,C2 +4567,PrimusC2 + File Nail trojan and legit usage for verizon,medium,C2 +4590,ICQTrojan,high,malware +4747,RPC-Backdoor - RPC over TCP/IP with the hard-coded port number 4747,medium,Persistence +5000,hardhatC2 and HRShell default port + other malwares and legit usages,medium,C2 +5001,FudgeC2 + spiderfoot and other malwares but also used by synology NAS and yahoo messenger,medium,C2 +5096,hardhatC2 default port,high,C2 +5321,Firehotcker trojan,high,malware +5400,BladeRunner and Back Construction trojans but also some games,medium,malware +5556,AlanFramework C2 default port and H0rtiga trojan,high,C2 +6666,kali default port - IRC botnets and RAT - CVE-2024-38112/Void Banshee,high,exploitation +6667,IRC channel used by botnet and multiple malwares but also legit usages,medium,malware +6722,default port for socks reverse proxy of XiebroC2,high,C2 +7096,hardhatC2 default port and other legit usages,high,C2 +7444,mythic C2 default port and legit vmware port,medium,C2 +7474,default port for bloodhound neo4j,medium,exploitation +7681,Supershell C2 default port,high,C2 +7682,Supershell C2 default port,high,C2 +7687,Neo4j default port,medium,exploitation +7712,cobaltstrike samples wih lumma stealer used this port,medium,C2 +7844,cloudfare tunnel,high,C2 +8022,MaccaroniC2 default port,high ,C2 +8848,DcRat,medium,malware +8888,POSHC2 default port but also legit usages,medium,exploitation +8936,MoonPeak malware,medium,C2 +8999,PrimusC2,medium,malware +9631,hardhatC2 default port and other legit usages,high,C2 +9936,MoonPeak malware,medium,C2 +9966,MoonPeak malware,medium,C2 +9988,Rbot-GR trojan and other legit usages,medium,malware +10002,multiple malwares,medium,malware +10426,Backdoor.Win32.Agent.cu,medium,malware +12122,Backdoor.Hellza server listening on this port,medium,malware +12345,netbus trojan and other malwares,high,malware +12346,netbus trojan and other malwares,high,malware +13333,Xmrig coinminer,high,Cryptominer +15555,Xmrig coinminer,high,Cryptominer +17300,Kuang2 trojan,high,malware +19999,Xmrig coinminer,high,Cryptominer +20034,netbus trojan and other malwares,high,malware +21802,HardhatC2 default port,high,C2 +27374,SubSeven backdoor and multiple other malwares,high,malware +30662,o365-attack-toolkit default port,high,exploitation +31335,Trinoo distributed attack tool port,high,exploitation +31337,Associated with various types of exploits, shellcode and command and control servers such as SliverC2. Also serves as ThunderShell default port, and was seen used by Back Orifice backdoor.,high,C2 +31338,Was seen being used by the Back Orifice backdoor and other malwares,high,malware +31785,Hack’a’Tack RAT,high,malware +31789,Hack’a’Tack RAT,high,malware +35000,evilqr,medium,exploitation +48101,W32.Blastclan.Worm,high,malware +50050,Sharpc2 and CobaltStrike default port,high,C2 +50501,TEMP.Veles used port-protocol mismatches on ports such as 443 - 4444 - 8531 and 50501 during C2,high,C2 +52935,C3 webcontroller default port,medium,C2 +53531,dnscat2 default port,high,C2 +54320,Back Orifice backdoor,medium,malware +55553,Metasploit RPC daemon default port, also used by Armitage team server,high,exploitation +57230,Covenant C2 default port,high,C2 +61466,Backdoor:Win32/Thething.F and telecommando trojan,medium,malware +65000,Devil RAT,medium,malware diff --git a/lookups/suspicious_ports_list.yml b/lookups/suspicious_ports_list.yml new file mode 100644 index 0000000000..4b060e9916 --- /dev/null +++ b/lookups/suspicious_ports_list.yml @@ -0,0 +1,11 @@ +name: suspicious_ports_list +date: 2025-07-01 +version: 1 +id: 5fa401d1-f0d4-4a6d-b3e4-db7cc45acc28 +author: mthcht, Splunk Threat Research Team +lookup_type: csv +description: A list of suspicious ports that are used or abused by threat actors, malware or PUA software. +match_type: +- WILDCARD(file) +min_matches: 1 +case_sensitive_match: false diff --git a/macros/cisco_network_visibility_module_flowdata.yml b/macros/cisco_network_visibility_module_flowdata.yml new file mode 100644 index 0000000000..eb93ad8dd8 --- /dev/null +++ b/macros/cisco_network_visibility_module_flowdata.yml @@ -0,0 +1,3 @@ +definition: sourcetype="cisco:nvm:flowdata" +description: customer specific splunk configurations(eg- index, source, sourcetype) for Cisco Network Visibility Module flow logs. Replace the macro definition with configurations for your Splunk Environment. +name: cisco_network_visibility_module_flowdata diff --git a/stories/cisco_network_visibility_module_analytics.yml b/stories/cisco_network_visibility_module_analytics.yml new file mode 100644 index 0000000000..bf9d3b0aff --- /dev/null +++ b/stories/cisco_network_visibility_module_analytics.yml @@ -0,0 +1,27 @@ +name: Cisco Network Visibility Module Analytics +id: cf276930-de9f-484c-9d92-f358534890a1 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +description: | + This analytic story provides a suite of detections built to analyze endpoint-based network telemetry captured by the Cisco Network Visibility Module (NVM). + It focuses on identifying suspicious and potentially malicious activity such as process injection, unauthorized downloads, network connections by non-network-aware processes, and potential command-and-control (C2) behavior, etc. + Leveraging the rich metadata from NVM, including process names, command-line arguments, user context, and module information, these detections provide high-fidelity insights into host behavior and outbound network activity. +narrative: | + Cisco Network Visibility Module (NVM), part of Cisco Secure Client (formerly AnyConnect), collects granular telemetry directly from endpoints to provide enhanced visibility into process-level network activity. + This includes detailed fields such as process names, parent-child relationships, command-line arguments, loaded modules, user accounts, and DNS destinations. + This analytic story leverages that context to detect threats across various tactics and techniques including Command and Control, Execution, Defense Evasion, and Credential Access. + It is particularly useful for detecting living-off-the-land (LOLBins) behavior, abuse of legitimate system processes, or exfiltration attempts from otherwise trusted binaries. +references: +- https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/anyconnect42/administration/guide/b_AnyConnect_Administrator_Guide_4-2/b_AnyConnect_Administrator_Guide_4-2_chapter_01100.pdf +- https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/Cisco-Secure-Client-5/admin/guide/nvm-collector-5-1-1-admin-guide.html +- https://community.cisco.com/t5/security-knowledge-base/cisco-network-visibility-nvm-collector/ta-p/4309825 +tags: + category: + - Adversary Tactics + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection From 544645b87bf99c86e0e7255a83f7ed5cc927095d Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Tue, 1 Jul 2025 23:07:46 +0200 Subject: [PATCH 07/21] Update suspicious_ports_list.csv --- lookups/suspicious_ports_list.csv | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/lookups/suspicious_ports_list.csv b/lookups/suspicious_ports_list.csv index 71c61ecce3..9314c3f120 100644 --- a/lookups/suspicious_ports_list.csv +++ b/lookups/suspicious_ports_list.csv @@ -4,10 +4,10 @@ dest_port,comment,confidence,category 1015,Doly trojan,high,malware 1042,Bla trojan,high,malware 1075,Backdoor.Win32.LanaFTP.k listening on this port,high,malware -1080,Was seen being used by multiple malware, and is also the default port of the pentest utility ligolo,medium,C2 +1080,Was seen being used by multiple malware and is also the default port of the pentest utility ligolo,medium,C2 1170,Psyber Stream Server - PSS,high,malware 1243,SubSeven backdoor,high,malware -1337,Was seen being used by multiple malware and red team or pentest utilities, such as empire, crackmapexec, icebreaker, KittyStager, Cyberghost VPN, gophish, gtunnel. The port is also associated with various other types of exploits or shellcode,high,exploitation +1337,Was seen being used by multiple malware and red team or pentest utilities such as empire; crackmapexec; icebreaker; KittyStager; Cyberghost VPN; gophish; gtunnel. The port is also associated with various other types of exploits or shellcode,high,exploitation 1981,Shockrave malware,high,malware 2001,Millennium Worm and multiple malwares,medium,malware 2773,SubSeven trojan and some backup services,medium,malware @@ -69,7 +69,7 @@ dest_port,comment,confidence,category 27374,SubSeven backdoor and multiple other malwares,high,malware 30662,o365-attack-toolkit default port,high,exploitation 31335,Trinoo distributed attack tool port,high,exploitation -31337,Associated with various types of exploits, shellcode and command and control servers such as SliverC2. Also serves as ThunderShell default port, and was seen used by Back Orifice backdoor.,high,C2 +31337,Associated with various types of exploits; shellcode and command and control servers such as SliverC2. Also serves as ThunderShell default port; and was seen used by Back Orifice backdoor.,high,C2 31338,Was seen being used by the Back Orifice backdoor and other malwares,high,malware 31785,Hack’a’Tack RAT,high,malware 31789,Hack’a’Tack RAT,high,malware @@ -80,7 +80,7 @@ dest_port,comment,confidence,category 52935,C3 webcontroller default port,medium,C2 53531,dnscat2 default port,high,C2 54320,Back Orifice backdoor,medium,malware -55553,Metasploit RPC daemon default port, also used by Armitage team server,high,exploitation +55553,Metasploit RPC daemon default port; also used by Armitage team server,high,exploitation 57230,Covenant C2 default port,high,C2 61466,Backdoor:Win32/Thething.F and telecommando trojan,medium,malware 65000,Devil RAT,medium,malware From b90359fd46d1d632ace9a2467516912de8ad2670 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Tue, 1 Jul 2025 23:11:48 +0200 Subject: [PATCH 08/21] fix rba and filter macro issue --- .../cisco_nvm___bits_download_from_file_sharing_website.yml | 2 +- .../cisco_nvm___outbound_connection_to_suspicious_port.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml index f158c19588..6b1db30d3f 100644 --- a/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___bits_download_from_file_sharing_website.yml @@ -78,7 +78,7 @@ rba: score: 30 threat_objects: - field: dest_hostname - type: other + type: domain tags: analytic_story: - Cisco Network Visibility Module Analytics diff --git a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml index d6d14d98c3..cdd58c79f1 100644 --- a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml +++ b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml @@ -41,7 +41,7 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest dest_port dest_port_category transport dest_port_metadata dest_port_confidence firstTime lastTime - | `cisco_nvm___outbound_connection_to_suspicious_port` + | `cisco_nvm___outbound_connection_to_suspicious_port_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. From 6527190e18ce429199871771eeacd87bff9f6889 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Tue, 1 Jul 2025 23:18:54 +0200 Subject: [PATCH 09/21] up version for ci overlords --- .../endpoint/windows_ingress_tool_transfer_using_explorer.yml | 4 ++-- .../cisco_secure_firewall___repeated_malware_downloads.yml | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml index 63b368136e..4a5685d7dd 100644 --- a/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml +++ b/detections/endpoint/windows_ingress_tool_transfer_using_explorer.yml @@ -1,7 +1,7 @@ name: Windows Ingress Tool Transfer Using Explorer id: 76753bab-f116-4ea3-8fb9-89b638be58a9 -version: 9 -date: '2025-05-02' +version: 10 +date: '2025-07-01' author: Teoderick Contreras, Splunk status: production type: Anomaly diff --git a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml index 97d2352c2d..fd3470330a 100644 --- a/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml +++ b/detections/network/cisco_secure_firewall___repeated_malware_downloads.yml @@ -1,7 +1,7 @@ name: Cisco Secure Firewall - Repeated Malware Downloads id: aeff2bb5-3483-48d4-9be8-c8976194be1e -version: 2 -date: '2025-05-02' +version: 3 +date: '2025-07-01' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly From 375dc32251b73d5b19889a7d839be95543735bdc Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Thu, 3 Jul 2025 00:32:11 +0200 Subject: [PATCH 10/21] oh wow, much detection --- ...m___curl_execution_with_insecure_flags.yml | 97 +++++++++++++++ ...twork_binary_making_network_connection.yml | 99 ++++++++++++++++ ...outbound_connection_to_suspicious_port.yml | 4 +- ...ous_download_from_file_sharing_website.yml | 111 ++++++++++++++++++ ..._from_process_without_command_argument.yml | 102 ++++++++++++++++ ...er_download_from_file_sharing_website.yml} | 60 +++++----- ...ndows_curl_download_to_suspicious_path.yml | 45 ++++--- .../endpoint/wmic_xsl_execution_via_url.yml | 108 +++++++++-------- 8 files changed, 536 insertions(+), 90 deletions(-) create mode 100644 detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml create mode 100644 detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml create mode 100644 detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml create mode 100644 detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_without_command_argument.yml rename detections/endpoint/{cisco_nvm___bits_download_from_file_sharing_website.yml => cisco_nvm___webserver_download_from_file_sharing_website.yml} (63%) diff --git a/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml new file mode 100644 index 0000000000..e7731d286d --- /dev/null +++ b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml @@ -0,0 +1,97 @@ +name: Cisco NVM - Curl Execution With Insecure Flags +id: cc695238-3117-4e60-aa83-4beac2a42c69 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects the use of `curl.exe` with insecure flags such as `-k`, `--insecure`, `--proxy-insecure`, or `--doh-insecure` + which disable TLS certificate validation. + It leverages Cisco Network Visibility Module (NVM) flow data and process arguments + to identify outbound connections initiated by curl where TLS checks were explicitly disabled. + This behavior may indicate an attempt to bypass certificate validation to connect to potentially untrusted or malicious endpoints, + a common tactic in red team operations, malware staging, or data exfiltration over HTTPS. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "curl.exe" + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | regex process_arguments="(?i)(? Date: Thu, 3 Jul 2025 00:38:21 +0200 Subject: [PATCH 11/21] fix ci error with name and filter macro --- ...co_nvm___suspicious_download_from_file_sharing_website.yml | 2 +- ...spicious_network_connection_from_process_with_no_args.yml} | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) rename detections/endpoint/{cisco_nvm___suspicious_network_connection_from_process_without_command_argument.yml => cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml} (99%) diff --git a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml index 88c9a62684..b31162cfe3 100644 --- a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml @@ -51,7 +51,7 @@ search: | process_integrity_level process_path process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest dest_port transport firstTime lastTime - | `cisco_nvm___suspicious_download_from_file_sharing_website` + | `cisco_nvm___suspicious_download_from_file_sharing_website_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_without_command_argument.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml similarity index 99% rename from detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_without_command_argument.yml rename to detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml index 40c57ee4e2..98f1eaf006 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_without_command_argument.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml @@ -1,4 +1,4 @@ -name: Cisco NVM - Suspicious Network Connection From Process Without Command Argument +name: Cisco NVM - Suspicious Network Connection From Process With No Args id: 54fa06c5-96a2-4406-a4a7-44d93ddbd173 version: 1 date: '2025-07-02' @@ -46,7 +46,7 @@ search: | process_integrity_level process_path process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest dest_port transport firstTime lastTime - | `cisco_nvm___suspicious_network_connection_from_process_without_command_argument_filter` + | `cisco_nvm___suspicious_network_connection_from_process_with_no_args_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. From b80d4fe2af343ee70ef8738c5f81d6eb8f95532d Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Thu, 3 Jul 2025 01:14:13 +0200 Subject: [PATCH 12/21] Update cisco_nvm___non_network_binary_making_network_connection.yml --- ...sco_nvm___non_network_binary_making_network_connection.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml index 5464220bb1..6c69f66cf7 100644 --- a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml +++ b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml @@ -72,13 +72,13 @@ drilldown_searches: earliest_offset: $info_min_time$ latest_offset: $info_max_time$ rba: - message: The host $src$ observed $process_name$ initiating a network connection to $dest$ over port $dest_port$, which is highly unusual + message: The host $src$ observed $process_path$ initiating a network connection to $dest$ over port $dest_port$, which is highly unusual risk_objects: - field: src type: system score: 40 threat_objects: - - field: process_name + - field: process_path type: process tags: analytic_story: From 0ab6a675563557af54838ac70a9e7e20ff92c7d3 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Fri, 4 Jul 2025 00:04:39 +0200 Subject: [PATCH 13/21] lemme add a couple more rules --- ...a_network_execution_without_url_in_cli.yml | 103 ++++++++++++++++++ ...twork_binary_making_network_connection.yml | 2 +- ...use_of_mshtml.dll_for_payload_download.yml | 94 ++++++++++++++++ ...om_archive_triggering_network_activity.yml | 93 ++++++++++++++++ ...ous_download_from_file_sharing_website.yml | 2 +- 5 files changed, 292 insertions(+), 2 deletions(-) create mode 100644 detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml create mode 100644 detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml create mode 100644 detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml diff --git a/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml new file mode 100644 index 0000000000..af1f36627f --- /dev/null +++ b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml @@ -0,0 +1,103 @@ +name: Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI +id: f2a9df84-9b01-4a21-9e3a-7aa1a217f69e +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects suspicious use of 'mshta.exe' or 'rundll32.exe' invoking 'mshtml.dll' + or the 'RunHTMLApplication' export without including a direct HTTP/HTTPS URL in the command line. + This pattern could be associated with obfuscated script execution used by threat actors during + initial access or payload staging. The absence of a visible URL may indicate attempts to evade static + detections by embedding the URL via string concatenation, encoding (e.g., hex), or indirect script loaders + like 'GetObject()'. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + ( + ( + process_name = "mshta.exe" + process_arguments IN ("*javascript*", "*vbscript*") + ) + OR + ( process_name = "rundll32.exe" AND + process_arguments = "*mshtml*" AND + process_arguments = "*RunHTMLApplication*" + ) + ) + NOT process_arguments IN ("*http://*", "*https://*") + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + False positives should be minimal as the presence of a network connection during such executions increases the likelihood of malicious behavior. +references: + - https://attack.mitre.org/techniques/T1218/005/ + - https://redcanary.com/blog/mshta-attack-technique/ + - https://lolbas-project.github.io/lolbas/Binaries/Rundll32/ + - https://learn.microsoft.com/en-us/windows/win32/api/mshtml/nf-mshtml-mshtml_runhtmlapplication +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ executed $process_name$ with potential obfuscated logic and initiated a network connection to $dest_hostname$ / $dest$ over $dest_port$. + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1218.005 + - T1059.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml index 6c69f66cf7..b53dc10dc1 100644 --- a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml +++ b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml @@ -79,7 +79,7 @@ rba: score: 40 threat_objects: - field: process_path - type: process + type: process_name tags: analytic_story: - Cisco Network Visibility Module Analytics diff --git a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml new file mode 100644 index 0000000000..9edcc60240 --- /dev/null +++ b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml @@ -0,0 +1,94 @@ +name: Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download +id: 18f0d27d-569e-4bc4-96e1-09b214fa73c0 +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects suspicious use of `rundll32.exe` in combination with `mshtml.dll` and the export `RunHTMLApplication`. + This behavior is often observed in malware to execute JavaScript or VBScript in memory, enabling payload staging or + bypassing script execution policies and bypassing the usage of the "mshta.exe" binary. + The detection leverages Cisco Network Visibility Module telemetry which offers network flow activity + along with process information such as command-line arguments + If confirmed malicious, this activity may indicate initial access or payload download. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "rundll32.exe" + process_arguments = "*mshtml*" + process_arguments IN ("*135*", "*RunHTMLApplication*") + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + `rundll32.exe` using `mshtml.dll` is rare in legitimate environments. However, edge cases might exist. Tuning may be needed in environments with custom automation scripts. +references: + - https://lolbas-project.github.io/lolbas/Binaries/Rundll32/ + - https://redcanary.com/blog/threat-detection/threat-research-questions/ + - https://twitter.com/n1nj4sec/status/1421190238081277959 + - https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt + - http://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_DETECTION_BYPASS.txt +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: $process_path$ was executed on $src$ leveraging the mshtml.dll and the RunHTMLApplication export to download a potentially suspicious file from $dest_hostname$. + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1218.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml new file mode 100644 index 0000000000..f93d08a08a --- /dev/null +++ b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml @@ -0,0 +1,93 @@ +name: Cisco NVM - Susp Script From Archive Triggering Network Activity +id: 8b07c2c9-0cde-4c44-9fa6-59dcf2b25777 +version: 1 +date: '2025-07-01' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic detects script execution (`wscript.exe` or `cscript.exe`) triggered from compressed files opened directly using + `explorer.exe`, `winrar.exe`, or `7zFM.exe`. + When a user double clicks on a ".js" file from within one of these compressed files. Its extracted temporally in the temp directory in folder with certain markers. + It leverages Cisco Network Visibility Module (NVM) flow data, in order to look for a specific parent/child relationship and an initiated network connection. + This behavior is exploited by threat actors such as Scarlet Goldfinch to deliver and run malicious scripts as an initial access technique. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + parent_process_name IN ("explorer.exe", "winrar.exe", "7zFM.exe") + process_name IN ("wscript.exe", "cscript.exe") + process_arguments = "*\\AppData\\Local\\Temp\\*" + process_arguments IN ("*\\rar*", "*\\7z*", "*.zip*") + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___susp_script_from_archive_triggering_network_activity_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some software installers or automation scripts may extract and run scripts from archive files in temporary directories. + However, it is uncommon for such scripts to initiate outbound network connections immediately upon extraction. + This behavior should be considered suspicious and investigated, especially in environments where such scripting is not typical. +references: + - https://redcanary.com/threat-detection-report/threats/scarlet-goldfinch/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: $process_path$ running from $parent_process_name$ with archive-related execution in Temp was observed from host $src$ + performing network a connection towards $dest$ / $dest_hostname$ over port $dest_port$. + risk_objects: + - field: src + type: system + score: 40 + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1059.005 + - T1204.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml index b31162cfe3..07068a9645 100644 --- a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml @@ -22,7 +22,7 @@ search: | process_name IN ( "curl.exe", "wmic.exe", "wscript.exe", "cscript.exe", "certutil.exe", "msiexec.exe", "hh.exe", "powershell.exe", "pwsh.exe", "powershell_ise.exe", - "installutil.exe", "certoc.exe" + "installutil.exe", "certoc.exe", "bitsadmin.exe" ) ) dest_hostname IN ( From 6b72dcb76f9391b454560bf61d004dc152380d47 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Fri, 4 Jul 2025 00:07:36 +0200 Subject: [PATCH 14/21] fix ci issues --- ...nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml} | 2 +- ...m___susp_script_from_archive_triggering_network_activity.yml | 1 + 2 files changed, 2 insertions(+), 1 deletion(-) rename detections/endpoint/{cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml => cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml} (98%) diff --git a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml similarity index 98% rename from detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml rename to detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml index 9edcc60240..b00c9423d1 100644 --- a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download.yml +++ b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml @@ -37,7 +37,7 @@ search: | process_integrity_level process_path process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime - | `cisco_nvm___rundll32_abuse_of_mshtml.dll_for_payload_download_filter` + | `cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. diff --git a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml index f93d08a08a..ed246f28d7 100644 --- a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml +++ b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml @@ -72,6 +72,7 @@ rba: - field: src type: system score: 40 + threat_objects: - field: process_path type: process_name tags: From 879259dd8b37d7833e529a8040fd97a337851a14 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Fri, 4 Jul 2025 02:21:13 +0200 Subject: [PATCH 15/21] map existing rclone analytic and add a dedicated nvm one --- ...rclone_execution_with_network_activity.yml | 106 ++++++++++++++++++ .../detect_rclone_command_line_usage.yml | 96 +++++++++------- 2 files changed, 162 insertions(+), 40 deletions(-) create mode 100644 detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml diff --git a/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml new file mode 100644 index 0000000000..c93941f43d --- /dev/null +++ b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml @@ -0,0 +1,106 @@ +name: Cisco NVM - Rclone Execution With Network Activity +id: 719f8c78-b20d-4bb9-8c33-6d1a762e7a9a +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This detection identifies execution of the file synchronization utility "rclone". + It leverages Cisco Network Visibility Module logs, specifically flow data in order to capture process executions + initiating network connections. + While rclone is a legitimate command-line tool for syncing data to cloud storage providers, it has been widely abused by threat actors for data exfiltration. + This analytic inspects process name and arguments for rclone and flags usage of suspicious flags. + If matched, this could indicate malicious usage for stealthy data exfiltration or cloud abuse. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + ( + process_name = "rclone.exe" + OR + ( + process_arguments = "* copy *" + process_arguments = "*\\\\*" + process_arguments IN ("*remote:*", "*mega:*", "*ftp:*", "*ftp1:*") + ) + OR + ( + process_arguments IN ("*remote:*", "*mega:*", "*ftp:*", "*ftp1:*") + process_arguments = "*--transfers" + process_arguments = "*--ignore-existing*" + process_arguments = "*--auto-confirm*" + ) + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___rclone_execution_with_network_activity_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Rclone is used legitimately in some backup or other workflows. Tune this rule based on known-good operational usage or restrict by known user/service accounts an specific folders or remote names. +references: + - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ + - https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/ + - https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ + - https://redcanary.com/blog/threat-detection/rclone-mega-extortion/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Rclone was executed on $src$ using flags $process_arguments$ and connected to $dest_hostname$ over $dest_port$. + risk_objects: + - field: src + type: system + score: 60 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1567.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/detect_rclone_command_line_usage.yml b/detections/endpoint/detect_rclone_command_line_usage.yml index 4f97b47f3e..4a4805250a 100644 --- a/detections/endpoint/detect_rclone_command_line_usage.yml +++ b/detections/endpoint/detect_rclone_command_line_usage.yml @@ -1,7 +1,7 @@ name: Detect RClone Command-Line Usage id: 32e0baea-b3f1-11eb-a2ce-acde48001122 -version: 11 -date: '2025-05-02' +version: 12 +date: '2025-07-04' author: Michael Haag, Splunk status: production type: TTP @@ -17,18 +17,28 @@ data_source: - Sysmon EventID 1 - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_rclone` Processes.process - IN ("*copy*", "*mega*", "*pcloud*", "*ftp*", "*--config*", "*--progress*", "*--no-check-certificate*", - "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", "*--multi-thread-streams*") +- Cisco Network Visibility Module Flow Data +search: | + | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where + `process_rclone` + Processes.process IN ( + "*copy*", "*mega*", "*pcloud*", "*ftp*", + "*--config*", "*--progress*", "*--no-check-certificate*", + "*--ignore-existing*", "*--auto-confirm*", "*--transfers*", + "*--multi-thread-streams*" + ) by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product - | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` - | `detect_rclone_command_line_usage_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `detect_rclone_command_line_usage_filter` +how_to_implement: | + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. @@ -37,27 +47,27 @@ how_to_implement: The detection is based on data that originates from Endpoint D the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: False positives should be limited as this is restricted to - the Rclone process name. Filter or tune the analytic as needed. +known_false_positives: | + False positives should be limited as this is restricted to the Rclone process name. Filter or tune the analytic as needed. references: -- https://redcanary.com/blog/rclone-mega-extortion/ -- https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations -- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ -- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ + - https://redcanary.com/blog/rclone-mega-extortion/ + - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations + - https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ + - https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ drilldown_searches: -- name: View the detection results for - "$user$" and "$dest$" - search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ -- name: View risk events for the last 7 days for - "$user$" and "$dest$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", - "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) - as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk - Message" values(analyticstories) as "Analytic Stories" values(annotations._all) - as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" - by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ + - name: View the detection results for - "$user$" and "$dest$" + search: '%original_detection_search% | search user = "$user$" dest = "$dest$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$user$" and "$dest$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", + "$dest$") starthoursago=168 | stats count min(_time) as firstTime max(_time) + as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk + Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ rba: message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to connect to a remote cloud service @@ -76,21 +86,27 @@ rba: type: process_name tags: analytic_story: - - DarkSide Ransomware - - Ransomware - - Black Basta Ransomware - - Cactus Ransomware + - DarkSide Ransomware + - Ransomware + - Black Basta Ransomware + - Cactus Ransomware + - Cisco Network Visibility Module Analytics asset_type: Endpoint mitre_attack_id: - T1020 product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud security_domain: endpoint tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog + - name: True Positive Test - Sysmon + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata \ No newline at end of file From e3bfb2da07239c4a5537c1075f89a6f8619b4398 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Sun, 6 Jul 2025 02:57:39 +0200 Subject: [PATCH 16/21] the final countdown --- ...stallation_of_typosquatted_python_pack.yml | 99 +++ ...ous_download_from_file_sharing_website.yml | 3 +- ...ous_file_download_via_headless_browser.yml | 132 ++++ ...k_connection_from_process_with_no_args.yml | 3 +- ...rk_connection_to_ip_lookup_service_api.yml | 105 ++++ ...uspicious_network_connection_via_msxsl.yml | 97 +++ lookups/typo_squatted_python_packages.csv | 569 ++++++++++++++++++ lookups/typo_squatted_python_packages.yml | 11 + 8 files changed, 1017 insertions(+), 2 deletions(-) create mode 100644 detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml create mode 100644 detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml create mode 100644 detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml create mode 100644 detections/endpoint/cisco_nvm___suspicious_network_connection_via_msxsl.yml create mode 100644 lookups/typo_squatted_python_packages.csv create mode 100644 lookups/typo_squatted_python_packages.yml diff --git a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml new file mode 100644 index 0000000000..8dbcaf6e40 --- /dev/null +++ b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml @@ -0,0 +1,99 @@ +name: Cisco NVM - Installation of Typosquatted Python Package +id: 5e3f6b44-42cb-4f8a-99f0-59e78a52ea1d +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: TTP +description: | + This analytic detects suspicious python package installations where the package name resembles popular Python libraries but may be typosquatted or slightly altered. + Typosquatting is a common technique used by attackers to trick users into installing malicious packages that mimic legitimate ones. + This detection leverages Cisco NVM flow telemetry and checks for pip or poetry package managers with the "install" or "add" flags, making outbound connections to package repository such as `pypi.org` with known or suspected typo package names. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + dest_hostname IN ("*.pythonhosted.org", "*pypi.org", "*python-poetry.org") + ( + (process_arguments = "*pip*" process_arguments = "*install*") + OR + (process_arguments = "*poetry*" process_arguments = "*add*") + ) + | rex field=process_arguments "(?i)(?:pip|poetry)[^|]*?\s+(?:install|add)\s+(?P[^\s\"']+)$" + | lookup typo_squatted_python_packages + typosquatted_package_name as package_name + OUTPUTNEW comment package_official_url + | where isnotnull(comment) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level + process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___installation_of_typosquatted_python_pack_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + In addition to this, the search make use of the lookup "typo_squatted_python_packages". Which needs to be configured and tuned. +known_false_positives: | + False positives should be very minimal to non existent, as the names of the packages in the lookup are all extracted from previously malicious packages. +references: + - https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218/ + - https://blog.checkpoint.com/securing-the-cloud/pypi-inundated-by-malicious-typosquatting-campaign/ + - https://rhisac.org/threat-intelligence/typosquatting-campaign-targets-python-developers-with-hundreds-of-malicious-libraries/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Host $src$ used pip or poetry to install a likely typosquatted python package "$package_name$" from $dest_hostname$ + risk_objects: + - field: src + type: system + score: 60 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1059 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml index 07068a9645..cec4329628 100644 --- a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml @@ -43,6 +43,7 @@ search: | values(module_hash_list) as module_hash_list values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` @@ -50,7 +51,7 @@ search: | parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash process_integrity_level process_path process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list - src dest dest_port transport firstTime lastTime + src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_download_from_file_sharing_website_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. diff --git a/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml new file mode 100644 index 0000000000..e10775d325 --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml @@ -0,0 +1,132 @@ +name: Cisco NVM - Suspicious File Download via Headless Browser +id: cd0e816f-f67d-4dbe-a153-480b546e867e +version: 1 +date: '2025-07-02' +author: Nasreddine Bencherchali, Splunk +status: production +type: TTP +description: | + This analytic identifies the use of Chromium-based browsers (like Microsoft Edge) running in headless mode with the `--dump-dom` argument. + This behavior has been observed in attack campaigns such as DUCKTAIL, where browsers are automated to stealthily download content from the internet using direct URLs or suspicious hosting platforms. + The detection focuses on identifying connections to known file-sharing domains or direct IPs extracted from command-line arguments and cross-checks those against the destination of the flow. + Since it leverages Cisco Network Visibility Module telemetry, the rule triggers only if a network connection is made. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + + ``` Usually the initiator of the connection is the child process, meaning the parent will contain the suspicious command.``` + + ( + parent_process_name IN ("brave.exe", "chrome.exe", "msedge.exe", "opera.exe", "vivaldi.exe") + OR + process_name IN ("brave.exe", "chrome.exe", "msedge.exe", "opera.exe", "vivaldi.exe") + ) + ( + (parent_process_arguments="*--headless*" parent_process_arguments="*--dump-dom*") + OR + (process_arguments="*--headless*" process_arguments="*--dump-dom*") + ) + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + + ``` In order to avoid matching with any public IP, we extract the IP value from the CommandLine and filter on it``` + + | rex field=parent_process_arguments "(?i)\\b(?:https?|ftp)://(?(?:\\d{1,3}\\.){3}\\d{1,3})" + | rex field=process_arguments "(?i)\\b(?:https?|ftp)://(?(?:\\d{1,3}\\.){3}\\d{1,3})" + | eval direct_ip_match=if(dest == extracted_ip_child, 1, if(dest == extracted_ip_parent, 1, 0)) + + | where ( + dest_hostname IN ( + "*.githubusercontent.com*", "*anonfiles.com*", "*cdn.discordapp.com*", "*ddns.net*", + "*dl.dropboxusercontent.com*", "*ghostbin.co*", "*glitch.me*", "*gofile.io*", + "*hastebin.com*", "*mediafire.com*", "*mega.nz*", "*onrender.com*", "*pages.dev*", + "*paste.ee*", "*pastebin.*", "*pastetext.net*", "*privatlab.*", + "*send.exploit.in*", "*sendspace.com*", "*storage.googleapis.com*", + "*storjshare.io*", "*supabase.co*", "*temp.sh*", "*transfer.sh*", "*trycloudflare.com*", + "*ufile.io*", "*w3spaces.com*", "*workers.dev*" + ) + OR direct_ip_match = 1 + ) + + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_file_download_via_headless_browser_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Some internal automation frameworks may invoke Chromium browsers in headless mode to programmatically access internal services or webpages. + These tools may occasionally download legitimate resources as part of their normal behavior. + Tuning based on command-line patterns or known dest hostnames may be required to avoid noise. +references: + - https://labs.withsecure.com/content/dam/labs/docs/WithSecure_Research_DUCKTAIL.pdf + - https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html + - https://x.com/mrd0x/status/1478234484881436672?s=12 + - https://developer.chrome.com/docs/chromium/headless +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Suspicious file download using the Chromium-based browser "$parent_process_name$" via the commandline $process_arguments$. + Observed on host $src$ communicating with $dest$ / $dest_hostname$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1105 + - T1059 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml index 98f1eaf006..3fac4a7f61 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml @@ -38,6 +38,7 @@ search: | values(module_hash_list) as module_hash_list values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` @@ -45,7 +46,7 @@ search: | parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash process_integrity_level process_path process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list - src dest dest_port transport firstTime lastTime + src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_from_process_with_no_args_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml new file mode 100644 index 0000000000..0e752836e7 --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml @@ -0,0 +1,105 @@ +name: Cisco NVM - Suspicious Network Connection to IP Lookup Service API +id: 568cb83e-d79e-4a23-85ec-6e1f6c30cb2f +version: 1 +date: '2025-07-04' +author: Nasreddine Bencherchali, Splunk, Janantha Marasinghe +status: production +type: Anomaly +description: | + This analytic identifies non-browser processes reaching out to public IP lookup or geolocation services, + such as `ipinfo.io`, `icanhazip.com`, `ip-api.com`, and others. + These domains are commonly used by legitimate tools, but their usage outside of browsers may indicate + network reconnaissance, virtual machine detection, or staging by malware. + This activity is observed in post-exploitation frameworks, stealer malware, and advanced threat actor campaigns. + The detection relies on Cisco Network Visibility Module (NVM) telemetry and excludes known browser + processes to reduce noise. +search: | + `cisco_network_visibility_module_flowdata` + dest_hostname IN ( + "*api.2ip.ua*", "*api.bigdatacloud.net*", "*api.ipify.org*", "*whatismyipaddress.com*", + "*canireachthe.net*", "*checkip.amazonaws.com*", "*checkip.dyndns.org*", "*curlmyip.com*", + "*db-ip.com*", "*edns.ip-api.com*", "*eth0.me*", "*freegeoip.app*", "*geoipy.com*", "*getip.pro*", + "*icanhazip.com*", "*ident.me*", "*ifconfig.io*", "*ifconfig.me*", "*ip-api.com*", "*ip.360.cn*", + "*ip.anysrc.net*", "*ip.taobao.com*", "*ip.tyk.nu*", "*ipaddressworld.com*", "*ipapi.co*", + "*ipconfig.io*", "*ipecho.net*", "*ipinfo.io*", "*ipip.net*", "*iplocation.net*", + "*ipof.in*", "*ipv6-test.com*", "*ipwho.is*", "*trackip.net*", "*inet-ip.info*", + "*jsonip.com*", "*myexternalip.com*", "*seeip.org*", "*wgetip.com*", + "*whatismyip.akamai.com*", "*whois.pconline.com.cn*", "*wtfismyip.com*", "*ip.cn" + ) + NOT process_name IN ( + "brave.exe", "chrome.exe", "firefox.exe", "iexplore.exe", "maxthon.exe", + "MicrosoftEdge.exe", "msedge.exe", "msedgewebview2.exe", "opera.exe", "safari.exe", + "seamonkey.exe", "vivaldi.exe", "whale.exe" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + Internal scripts or agents performing network checks may query IP geolocation services. + Tune by excluding known tools or adding internal allowlists for destination domains or process names and commandlines. +references: + - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/network_connection/net_connection_win_domain_external_ip_lookup.yml + - https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-302a +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: The host $src$ made a network request to IP lookup service $dest_hostname$ using suspicious process $process_path$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1590.005 + - T1016 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_via_msxsl.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_via_msxsl.yml new file mode 100644 index 0000000000..29d799ebe3 --- /dev/null +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_via_msxsl.yml @@ -0,0 +1,97 @@ +name: Cisco NVM - Suspicious Network Connection Initiated via MsXsl +id: 1cbcf75f-0e45-4f29-8c1b-7fcd7e55cc55 +version: 1 +date: '2025-07-03' +author: Nasreddine Bencherchali, Splunk +status: production +type: Anomaly +description: | + This analytic identifies the use of `msxsl.exe` initiating a network connection to a non-private IP address. + Although `msxsl.exe` is a legitimate Microsoft utility used to apply XSLT transformations, adversaries can abuse it + to execute arbitrary code or load external resources in an evasive manner. + This detection leverages Cisco NVM telemetry to identify potentially malicious use of `msxsl.exe` making network connections + that may indicate command and control (C2) or data exfiltration activity. +data_source: + - Cisco Network Visibility Module Flow Data +search: | + `cisco_network_visibility_module_flowdata` + process_name = "msxsl.exe" + NOT dest IN ( + "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10", + "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32", + "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24", + "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24", + "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1" + ) + | stats count min(_time) as firstTime max(_time) as lastTime + values(parent_process_arguments) as parent_process_arguments + values(process_arguments) as process_arguments + values(parent_process_hash) as parent_process_hash + values(process_hash) as process_hash + values(module_name_list) as module_name_list + values(module_hash_list) as module_hash_list + values(dest_port) as dest_port + values(aliul) as additional_logged_in_users_list + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level + process_path process_integrity_level process_id transport + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | table + parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash + process_integrity_level process_path process_arguments process_hash process_id + additional_logged_in_users_list module_name_list module_hash_list + src dest_hostname dest dest_port transport firstTime lastTime + | `cisco_nvm___suspicious_network_connection_initiated_via_msxsl_filter` +how_to_implement: | + This search requires Network Visibility Module logs, which includes the flow data sourcetype. + This search uses an input macro named `cisco_network_visibility_module_flowdata`. + We strongly recommend that you specify your environment-specific configurations + (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + Replace the macro definition with configurations for your Splunk environment. + The search also uses a post-filter macro designed to filter out known false positives. + The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). +known_false_positives: | + False positives may occur in development or administrative environments where msxsl.exe is used + for legitimate XML transformations. However, its use is uncommon in standard user activity + and should be reviewed in most environments. +references: + - https://lolbas-project.github.io/lolbas/OtherMSBinaries/Msxsl/ +drilldown_searches: + - name: View the detection results for - "$src$" + search: '%original_detection_search% | search src = "$src$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$src$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") starthoursago=168 | stats count min(_time) + as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) + as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) + as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" + by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +rba: + message: Host $src$ used msxsl.exe to initiate a suspicious network connection to $dest$ + risk_objects: + - field: src + type: system + score: 40 + threat_objects: + - field: process_path + type: process_name +tags: + analytic_story: + - Cisco Network Visibility Module Analytics + asset_type: Endpoint + mitre_attack_id: + - T1220 + product: + - Splunk Enterprise + - Splunk Enterprise Security + security_domain: endpoint +tests: + - name: True Positive Test - Cisco NVM + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log + source: not_applicable + sourcetype: cisco:nvm:flowdata diff --git a/lookups/typo_squatted_python_packages.csv b/lookups/typo_squatted_python_packages.csv new file mode 100644 index 0000000000..2242a44372 --- /dev/null +++ b/lookups/typo_squatted_python_packages.csv @@ -0,0 +1,569 @@ +typosquatted_package_name,comment,package_official_url +*aasyncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*assyncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyincio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncci*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynccio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynci*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncii*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynciio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncioi*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyncioo*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynciooo*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asynncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*asyyncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*aysncio*,"Potential typo squatting, variations of asyncio","https://pypi.org/project/asyncio/" +*beaitifulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaitifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaotifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaufifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beaurifulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifilsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifilsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautiflulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautiflulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifolsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifoulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifuklsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifuksoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifullsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifullsooup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoul*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoupe*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifulsoupo*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautifuosoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautilfulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautyfulsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beautysoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beuatiflsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beutifullsoup*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*beutifulsoop*,"Potential typo squatting, variations of beautifulsoup","https://pypi.org/project/BeautifulSoup/" +*bibp-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*biip-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-u8ls*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uitls*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-util*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilds*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utile*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utiles*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilos*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilss*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utilz*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utisl*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utjls*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-utlils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uttils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bip-uutils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bipp-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bips-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*biup-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bop-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bpi-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bup-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*bupi-utils*,"Potential typo squatting, variations of bip-utils","https://pypi.org/project/bip-utils/" +*capmoneercloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsstercloudcliennt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsstercloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterccloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclenet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclenit*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliant*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclieent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclieet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclien*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliend*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliendt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclienet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliennt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclientt*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcliient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclinent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclinet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudclouidclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercloudcluodclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouddclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouddlient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouidclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterclouudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercludclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercoudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonstercouldclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmonsterrcloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmosterclouclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclieent*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclienet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclient*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*capmostercloudclinet*,"Potential typo squatting, variations of capmonstercloudclient","https://pypi.org/project/capmonstercloudclient/" +*cilorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*clolorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*cloroma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colaroma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colomara*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorahma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramae*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramah*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramal*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramaz*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorame*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramia*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramka*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramna*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramo*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramoo*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramqa*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramqs*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramu*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramwa*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramws*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramxa*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramxs*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramza*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloramzs*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorayma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorhrama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorm*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colormma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*coloroama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorram*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colorramma*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colouorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*colprama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*corlorama*,"Potential typo squatting, variations of colorama","https://pypi.org/project/colorama/" +*cstmotkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cuatomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cusgtomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cusromtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custm*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custmtokinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custogtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custohtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custojmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custojtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custoktkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customekinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtikinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtiknter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtjinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkfnter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkibter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkihter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkimter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinber*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinet*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinetr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinger*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkingter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinrer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintar*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinte*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinted*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinteer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintert*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintet*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintre*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintrer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintrr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkintwr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkinyer*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitenr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkiter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitner*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitnerr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkitnre*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkiyter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkjnter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkknter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkniter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkniterr*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtknster*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtknter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkwnter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*customtkznter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custontkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custoqtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotkminter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custotminter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custoumtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custpmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custrmtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custumtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*custvomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cutomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cuwtomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*cuxtomtkinter*,"Potential typo squatting, variations of customtkinter","https://pypi.org/project/customtkinter/" +*maptplotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplftlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpliotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplkotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpllotb*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpllotib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplolplib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matploltlab*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matploltlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplootib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matploptlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplorlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotblib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotkib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotklib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlbib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlig*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotllib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlob*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlpib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlr*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotltib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlub*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotlyib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotoib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotpib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplottbib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplottib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplottlab*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotvib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplotvlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplptlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplrtib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplrtlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matpltotlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplttlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*matplutlib*,"Potential typo squatting, variations of matplotlib","https://pypi.org/project/matplotlib/ " +*oillow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*p-cord*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*p8llow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*p9llow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pi-cord*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilkow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pill9w*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilliow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilliw*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pillkw*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pillo2*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilloa*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilloo*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilloq*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pillox*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pilpow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*piolow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*piplow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pirlow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pjllow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*plaawright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/ " +*plauwright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plawwright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plawyright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playrwight*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwirght*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrght*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrgiht*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrgith*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrigght*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrigh*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrightt*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrigth*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwrihgt*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*playwritgh*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plyawright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*plywright*,"Potential typo squatting, variations of playwright","https://pypi.org/project/playwright/" +*pollow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*pqtorch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pttorch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pullow*,"Potential typo squatting, variations of pillow","https://pypi.org/project/pillow/" +*py-c0ard*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c0crd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c0dd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c0red*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-c9rd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cdord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cird*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-ckord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-ckrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-co4d*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coad*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cobrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cocd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cod*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-codrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coed*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coerd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cofd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cofrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coird*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cojrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coordd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-coqrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corad*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corddd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corde*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordf*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordq*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordr*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordv*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordw*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cordx*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corf*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corfd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corg*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corid*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cortd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corwd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corx*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-corxd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cotd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cotrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cowrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cozd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cpord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cprd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-crd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-crodd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cwrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cxrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-cyrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-czrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-vord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*py-xord*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pycjrd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pycordde*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pycordwd*,"Potential typo squatting, variations of py-cord","https://pypi.org/project/py-cord/" +*pygacme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaeme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaime*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamke*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamm*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamne*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamr*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamse*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygamw*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygane*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaome*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygaqme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygarme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygawme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygazme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygfame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygfme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pyghame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygmme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygqame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygqme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygume*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygvame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygxme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pygzme*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pzgame*,"Potential typo squatting, variations of pygame","https://pypi.org/project/pygame/" +*pytarch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytbrch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytcrch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pythrch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytirch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytlrc*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytoich*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorbch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcb*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcdh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchb*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchc*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchg*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchj*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchv*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorchy*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcm*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorcu*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytordh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytorqh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytprch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytroce*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pytrosh*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*pztorch*,"Potential typo squatting, variations of pytorch","https://pypi.org/project/pytorch/" +*rensoflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*reqeist*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeosts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeuste*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeustx*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeustz*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqeyst*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqirements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiremnets*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiremnts*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiurements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiurementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqiuremnets*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*reqjuests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqoests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqquest*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqsests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requas*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requeits*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requeksts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requekts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requeqsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesgt*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesks*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesqs*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesrts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requestr*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesuts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesxs*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesxt*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requesxts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requetsa*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requetsq*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requetsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requewsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requiements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requierement*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requierments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirementstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirementsxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiiremments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiiremnts*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiirments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremants*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremeents*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremenstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremenstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementss*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementst*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementsttx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxtt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxtx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementstxxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementtsxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxtt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirementxxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetns*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetnstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremetstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremmentstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremmentxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremmentxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnets*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnetstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnetxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremnts*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremntstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremntstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremntxtxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiremtns*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmeents*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirment*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentss*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentstx*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirmentstxtt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirrementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requirtements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiurement*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requiurementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requksts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requnests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requrementstxt*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requriements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requriments*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*requssts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requstss*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requxsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requyests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*requzsts*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reqzests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*reuirements*,"Potential typo squatting, variations of the file requirements.txt","N/A" +*seleenim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleenimu*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleeniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleinium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleiniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleinuim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleiumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemiumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemni*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemnim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemnium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selemniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenimn*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selennim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selennuim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenuimm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selenyum*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seleunium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seliniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*seliniumn*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selinum*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selleium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selleniium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*sellenim*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selleniumm*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*sellinium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*selunium*,"Potential typo squatting, variations of selenium","https://pypi.org/project/selenium/" +*sijplejso*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*sijplejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simepljson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simolejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpejso*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpjson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpkejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejason*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejdon*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejsoh*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simplejsoj*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*simpoejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*siplejason*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*sjimplejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*sjmplejson*,"Potential typo squatting, variations of simplejson","https://pypi.org/project/simplejson/" +*temsorflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensnflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensobflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofklow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofl9w*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofla*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflaow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofleow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofliw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofllow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofloaw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflod*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflolw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflom*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflomw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflonw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflor*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflouw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflpw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflqw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflsw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflw*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensoflxow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensofpow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensogflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensourflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*tensxoflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*trnsorflow*,"Potential typo squatting, variations of tensorflow","https://pypi.org/project/tensorflow/" +*pyquest*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" +*ultrarequests*,"Potential typo squatting, variations of requests","https://pypi.org/project/requests/" diff --git a/lookups/typo_squatted_python_packages.yml b/lookups/typo_squatted_python_packages.yml new file mode 100644 index 0000000000..676f4a7d9e --- /dev/null +++ b/lookups/typo_squatted_python_packages.yml @@ -0,0 +1,11 @@ +name: typo_squatted_python_packages +date: 2025-07-05 +version: 1 +id: cd309a8c-90d8-4c0d-98bf-70e8f5296a1e +author: Nasreddine Bencherchali, Splunk Threat Research Team +lookup_type: csv +description: A list of known typo squatted python packages +match_type: +- WILDCARD(typosquatted_package_name) +min_matches: 1 +case_sensitive_match: false From afe099158973dc452b737f66e726b1002463a556 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Sun, 6 Jul 2025 03:00:43 +0200 Subject: [PATCH 17/21] fix incorrect names and filter macros --- ...cisco_nvm___installation_of_typosquatted_python_package.yml} | 2 +- ...nvm___suspicious_network_connection_initiated_via_msxsl.yml} | 0 2 files changed, 1 insertion(+), 1 deletion(-) rename detections/endpoint/{cisco_nvm___installation_of_typosquatted_python_pack.yml => cisco_nvm___installation_of_typosquatted_python_package.yml} (98%) rename detections/endpoint/{cisco_nvm___suspicious_network_connection_via_msxsl.yml => cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml} (100%) diff --git a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml similarity index 98% rename from detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml rename to detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml index 8dbcaf6e40..c127cc4158 100644 --- a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_pack.yml +++ b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml @@ -43,7 +43,7 @@ search: | process_integrity_level process_path process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime - | `cisco_nvm___installation_of_typosquatted_python_pack_filter` + | `cisco_nvm___installation_of_typosquatted_python_package_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_via_msxsl.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml similarity index 100% rename from detections/endpoint/cisco_nvm___suspicious_network_connection_via_msxsl.yml rename to detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml From cb8f4bb6f3a34f7d2722452de71635785b47b671 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 7 Jul 2025 17:13:15 +0200 Subject: [PATCH 18/21] Update removed/deprecation_mapping.YML --- removed/deprecation_mapping.YML | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/removed/deprecation_mapping.YML b/removed/deprecation_mapping.YML index 783e93e3bf..69417fd8e3 100644 --- a/removed/deprecation_mapping.YML +++ b/removed/deprecation_mapping.YML @@ -1,16 +1,16 @@ detections: - content: Windows InstallUtil Uninstall Option with Network - removed_in_version: 5.11.0 + removed_in_version: 5.12.0 reason: Detection has been deprecated as its scope is already covered by "Windows InstallUtil Remote Network Connection". replacement_content: - Windows InstallUtil Remote Network Connection - content: Any Powershell DownloadString - removed_in_version: 5.11.0 + removed_in_version: 5.12.0 reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management. replacement_content: - Windows File Download Via PowerShell - content: Any Powershell DownloadFile - removed_in_version: 5.11.0 + removed_in_version: 5.12.0 reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management. replacement_content: - Windows File Download Via PowerShell From 91c6bd2d13c5bb087a93a3e350eb8436d6ceff9a Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 7 Jul 2025 17:18:19 +0200 Subject: [PATCH 19/21] Apply suggestion from @nasbench --- detections/endpoint/attacker_tools_on_endpoint.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 1ed2970fdd..4c8c68f2a8 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,7 +1,7 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 version: 13 -date: '2025-07-03' +date: '2025-07-07' author: Bhavin Patel, Splunk, sventec, Github Community status: production type: TTP From 584ed27ec426080673f448045cc910efcba97222 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 7 Jul 2025 17:22:35 +0200 Subject: [PATCH 20/21] Update attacker_tools_on_endpoint.yml --- detections/endpoint/attacker_tools_on_endpoint.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/attacker_tools_on_endpoint.yml b/detections/endpoint/attacker_tools_on_endpoint.yml index 4c8c68f2a8..0de2a89b07 100644 --- a/detections/endpoint/attacker_tools_on_endpoint.yml +++ b/detections/endpoint/attacker_tools_on_endpoint.yml @@ -1,6 +1,6 @@ name: Attacker Tools On Endpoint id: a51bfe1a-94f0-48cc-b4e4-16a110145893 -version: 13 +version: 12 date: '2025-07-07' author: Bhavin Patel, Splunk, sventec, Github Community status: production From 61f635161ea7eed402df2519916604d3626757c0 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali Date: Mon, 7 Jul 2025 18:51:58 +0200 Subject: [PATCH 21/21] update by clause --- ...isco_nvm___curl_execution_with_insecure_flags.yml | 6 +++--- ...__installation_of_typosquatted_python_package.yml | 7 +++---- ...or_mshta_network_execution_without_url_in_cli.yml | 6 +++--- ..._non_network_binary_making_network_connection.yml | 6 +++--- ..._nvm___outbound_connection_to_suspicious_port.yml | 12 ++++++------ ..._nvm___rclone_execution_with_network_activity.yml | 6 +++--- ...ll32_abuse_of_mshtml_dll_for_payload_download.yml | 6 +++--- ...ript_from_archive_triggering_network_activity.yml | 6 +++--- ...suspicious_download_from_file_sharing_website.yml | 6 +++--- ...suspicious_file_download_via_headless_browser.yml | 6 +++--- ..._network_connection_from_process_with_no_args.yml | 6 +++--- ...icious_network_connection_initiated_via_msxsl.yml | 7 +++---- ...s_network_connection_to_ip_lookup_service_api.yml | 6 +++--- ..._webserver_download_from_file_sharing_website.yml | 9 +++++---- 14 files changed, 47 insertions(+), 48 deletions(-) diff --git a/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml index e7731d286d..4a4cc8fbb8 100644 --- a/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml +++ b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml @@ -35,12 +35,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___curl_execution_with_insecure_flags_filter` @@ -77,7 +77,7 @@ rba: type: system score: 30 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml index c127cc4158..23861299a6 100644 --- a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml +++ b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml @@ -34,13 +34,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level - process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___installation_of_typosquatted_python_package_filter` @@ -79,7 +78,7 @@ rba: type: system score: 60 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml index af1f36627f..f31fced3ad 100644 --- a/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml +++ b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml @@ -38,12 +38,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli_filter` @@ -82,7 +82,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml index b53dc10dc1..60f9abcc4e 100644 --- a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml +++ b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml @@ -35,12 +35,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___non_network_binary_making_network_connection_filter` @@ -78,7 +78,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml index c6a8899d4e..0f8d7d9550 100644 --- a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml +++ b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml @@ -30,17 +30,17 @@ search: | values(module_hash_list) as module_hash_list values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | lookup suspicious_ports_list dest_port OUTPUTNEW comment as dest_port_metadata confidence as dest_confidence category as dest_port_category | where isnotnull(dest_port_metadata) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list - src dest dest_port dest_port_category transport dest_port_metadata dest_port_confidence - firstTime lastTime + src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___outbound_connection_to_suspicious_port_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. @@ -76,8 +76,8 @@ rba: type: system score: 30 threat_objects: - - field: process_path - type: process + - field: process_name + type: process_name tags: analytic_story: - Cisco Network Visibility Module Analytics diff --git a/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml index c93941f43d..825b83b0de 100644 --- a/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml +++ b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml @@ -42,12 +42,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___rclone_execution_with_network_activity_filter` @@ -86,7 +86,7 @@ rba: type: system score: 60 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml index b00c9423d1..ff83eb50e0 100644 --- a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml +++ b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml @@ -29,12 +29,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download_filter` @@ -74,7 +74,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml index ed246f28d7..120f8e623e 100644 --- a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml +++ b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml @@ -29,12 +29,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___susp_script_from_archive_triggering_network_activity_filter` @@ -73,7 +73,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml index cec4329628..7d5739263c 100644 --- a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml @@ -44,12 +44,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_download_from_file_sharing_website_filter` @@ -92,7 +92,7 @@ rba: type: system score: 30 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml index e10775d325..91444e9e9a 100644 --- a/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml +++ b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml @@ -64,12 +64,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_file_download_via_headless_browser_filter` @@ -111,7 +111,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml index 3fac4a7f61..48b1e2beda 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml @@ -39,12 +39,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_from_process_with_no_args_filter` @@ -82,7 +82,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml index 29d799ebe3..fd4adcad89 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml @@ -33,13 +33,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level - process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_initiated_via_msxsl_filter` @@ -77,7 +76,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml index 0e752836e7..f169459f60 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml @@ -41,12 +41,12 @@ search: | values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list values(dest_hostname) as dest_hostname - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api_filter` @@ -84,7 +84,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name tags: analytic_story: diff --git a/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml index fbb433f480..1209802782 100644 --- a/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml @@ -35,14 +35,15 @@ search: | values(module_hash_list) as module_hash_list values(dest_port) as dest_port values(aliul) as additional_logged_in_users_list - by src dest parent_process_path parent_process_integrity_level process_path process_integrity_level process_id transport + values(dest_hostname) as dest_hostname + by src dest parent_process_path parent_process_integrity_level process_path process_name process_integrity_level process_id transport | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table parent_process_integrity_level parent_process_path parent_process_arguments parent_process_hash - process_integrity_level process_path process_arguments process_hash process_id + process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list - src dest dest_port transport firstTime lastTime + src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___webserver_download_from_file_sharing_website_filter` how_to_implement: | This search requires Network Visibility Module logs, which includes the flow data sourcetype. @@ -67,7 +68,7 @@ rba: type: system score: 40 threat_objects: - - field: process_path + - field: process_name type: process_name drilldown_searches: - name: View the detection results for - "$src$"