Detection rules › YARA-L
Recon Suspicious Commands CISA Report
Detects suspicious commands as identified in CISA Living off the Land pdf. Alone they may be normal but in concert, they may be worth looking into
References
Event coverage
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Rule body yaral
/*
* Copyright 2023 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* https://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
rule recon_suspicious_commands_cisa_report {
meta:
author = "Google Cloud Security"
description = "Detects suspicious commands as identified in CISA Living off the Land pdf. Alone they may be normal but in concert, they may be worth looking into"
rule_id = "mr_66edb4f7-a7e2-4ce6-a247-d09319b7eeea"
rule_name = "Recon Suspicious Commands CISA Report"
type = "hunt"
platform = "Windows"
data_source = "microsoft sysmon, microsoft windows events"
reference = "https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF"
severity = "Low"
priority = "Low"
events:
$process.metadata.event_type = "PROCESS_LAUNCH"
$process.principal.hostname = $hostname
$process.target.process.command_line = $command_line
// cisa report referenced cmd /c in their report throughout, can filter this in/out for tuning as needed
// other wmic switches like /user and /password, these have been excluded to focus on the commands being issued since local access does not require these
(
re.regex($process.target.process.command_line, `(|cmd.*/c).*7z.*a.*-p.*c:\\windows\\temp\\.*.7z`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*c:\\Windows\\system32\\pcwrun.exe.*c:\\Users\\Administrator\\Desktop\\Win.exe`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c|cmdbak.*/c).*ping.*-n.*1.*127\.0\.0\.1.*c:\\Windows\\temp\\(putty|tmp).log`) nocase or
// The following line could be swapped for the previous line for a looser match. It was observed during testing that a c2 running powershell logged putty.log as a file creation but not in the command line process event
//re.regex($process.target.process.command_line, `(|cmd.*/c).*ping.*-n.*1.*127\.0\.0\.1`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*dir.*127\.0\.0\.1\\c\$.*/od`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*ping.*-a.*-n.*1`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*wmic.*process.*call.*create.*net.*stop.*C:\\Windows\\Temp\\tmp.log"`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*\\ADMIN\$\\__.*2>&1`) nocase or
//The following line could be swapped for the previous line for a looser match, but potentially noisier
//re.regex($process.target.process.command_line, `(|cmd.*/c).*\\ADMIN\$\\__`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*net.*use.*127\.0\.0\.1\\ipc\$.*/y.*/d`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*powershell.*start-process.*-filepath.*c:\\windows\\temp\\.*.bat.*-windowstyle.*Hidden`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*rar\.exe.*a.*c:\\Windows\\temp\\.*D:\\.*`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*wmic.*cmd.*/c.*whoami`) nocase or
re.regex($process.target.process.command_line, `(|cmd.*/c).*xcopy.*c:\\windows\\temp\\hp.*d:\\`) nocase
)
match:
$hostname over 15m
outcome:
$risk_score = 35
$event_count = count_distinct($process.metadata.id)
$unique_command_line_threshold = 5
// added to populate alert graph with additional context
// Commented out principal.hostname because it is already represented in graph as match variable. If match changes, can uncomment to add to results
//$principal_hostname = array_distinct($process.principal.hostname)
$principal_process_pid = array_distinct($process.principal.process.pid)
$principal_process_command_line = array_distinct($process.principal.process.command_line)
$principal_process_file_sha256 = array_distinct($process.principal.process.file.sha256)
$principal_process_file_full_path = array_distinct($process.principal.process.file.full_path)
$principal_process_product_specific_process_id = array_distinct($process.principal.process.product_specific_process_id)
$principal_process_parent_process_product_specific_process_id = array_distinct($process.principal.process.parent_process.product_specific_process_id)
$target_process_pid = array_distinct($process.target.process.pid)
$target_process_command_line = array_distinct($process.target.process.command_line)
$target_process_file_sha256 = array_distinct($process.target.process.file.sha256)
$target_process_file_full_path = array_distinct($process.target.process.file.full_path)
$target_process_product_specific_process_id = array_distinct($process.target.process.product_specific_process_id)
$principal_user_userid = array_distinct($process.principal.user.userid)
condition:
// modify the condition value for command line to throttle how many of these unique commands can be seen until the rule is triggered
$process and #command_line > 5
}
Detection logic
Fires when at least one $process event in the 15m window and $command_line occurs more than 5 times in the 15m window.
Events
$process
target.process.command_line matches "(|cmd.*/c).*7z.*a.*-p.*c:\\windows\\temp\\.*.7z"target.process.command_line matches "(|cmd.*/c).*c:\\Windows\\system32\\pcwrun.exe.*c:\\Users\\Administrator\\Desktop\\Win.exe"target.process.command_line matches "(|cmd.*/c|cmdbak.*/c).*ping.*-n.*1.*127\.0\.0\.1.*c:\\Windows\\temp\\(putty|tmp).log"target.process.command_line matches "(|cmd.*/c).*dir.*127\.0\.0\.1\\c\$.*/od"target.process.command_line matches "(|cmd.*/c).*ping.*-a.*-n.*1"target.process.command_line matches "(|cmd.*/c).*wmic.*process.*call.*create.*net.*stop.*C:\\Windows\\Temp\\tmp.log""target.process.command_line matches "(|cmd.*/c).*\\ADMIN\$\\__.*2>&1"target.process.command_line matches "(|cmd.*/c).*net.*use.*127\.0\.0\.1\\ipc\$.*/y.*/d"target.process.command_line matches "(|cmd.*/c).*powershell.*start-process.*-filepath.*c:\\windows\\temp\\.*.bat.*-windowstyle.*Hidden"target.process.command_line matches "(|cmd.*/c).*rar\.exe.*a.*c:\\Windows\\temp\\.*D:\\.*"target.process.command_line matches "(|cmd.*/c).*wmic.*cmd.*/c.*whoami"target.process.command_line matches "(|cmd.*/c).*xcopy.*c:\\windows\\temp\\hp.*d:\\"
Correlation
Outcome
Fields the detection emits on a match. $risk_score drives alerting; Chronicle surfaces the rest on the detection.
| Field | Expression |
|---|---|
risk_score | 35 |
event_count | count_distinct($process.metadata.id) |
unique_command_line_threshold | 5 |
principal_process_pid | array_distinct($process.principal.process.pid) |
principal_process_command_line | array_distinct($process.principal.process.command_line) |
principal_process_file_sha256 | array_distinct($process.principal.process.file.sha256) |
principal_process_file_full_path | array_distinct($process.principal.process.file.full_path) |
principal_process_product_specific_process_id | array_distinct($process.principal.process.product_specific_process_id) |
principal_process_parent_process_product_specific_process_id | array_distinct($process.principal.process.parent_process.product_specific_process_id) |
target_process_pid | array_distinct($process.target.process.pid) |
target_process_command_line | array_distinct($process.target.process.command_line) |
target_process_file_sha256 | array_distinct($process.target.process.file.sha256) |
target_process_file_full_path | array_distinct($process.target.process.file.full_path) |
target_process_product_specific_process_id | array_distinct($process.target.process.product_specific_process_id) |
principal_user_userid | array_distinct($process.principal.user.userid) |