Detection rules › Sigma

First Time Seen Remote Named Pipe - Zeek

Status
test
Severity
high
Log source
product zeek, service smb_files
Author
Samir Bousseaden, @neu5ron, Tim Shelton
Source
github.com/SigmaHQ/sigma

This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes

MITRE ATT&CK coverage

Rule body yaml

title: First Time Seen Remote Named Pipe - Zeek
id: 021310d9-30a6-480a-84b7-eaa69aeb92bb
related:
    - id: 52d8b0c6-53d6-439a-9e41-52ad442ad9ad
      type: derived
status: test
description: This detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
references:
    - https://twitter.com/menasec1/status/1104489274387451904
author: Samir Bousseaden, @neu5ron, Tim Shelton
date: 2020-04-02
modified: 2022-12-27
tags:
    - attack.lateral-movement
    - attack.t1021.002
logsource:
    product: zeek
    service: smb_files
detection:
    selection:
        path: '\\\\\*\\IPC$' # Looking for the string \\*\IPC$
    filter_keywords:
        - 'samr'
        - 'lsarpc'
        - 'winreg'
        - 'netlogon'
        - 'srvsvc'
        - 'protected_storage'
        - 'wkssvc'
        - 'browser'
        - 'netdfs'
        - 'svcctl'
        - 'spoolss'
        - 'ntsvcs'
        - 'LSM_API_service'
        - 'HydraLsPipe'
        - 'TermSrv_API_service'
        - 'MsFteWds'
    condition: selection and not 1 of filter_*
falsepositives:
    - Update the excluded named pipe to filter out any newly observed legit named pipe
level: high

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_*

Stage 1: selection

selection:
    path: '\\\\\*\\IPC$'

Stage 2: not filter_keywords

filter_keywords:
    - 'samr'
    - 'lsarpc'
    - 'winreg'
    - 'netlogon'
    - 'srvsvc'
    - 'protected_storage'
    - 'wkssvc'
    - 'browser'
    - 'netdfs'
    - 'svcctl'
    - 'spoolss'
    - 'ntsvcs'
    - 'LSM_API_service'
    - 'HydraLsPipe'
    - 'TermSrv_API_service'
    - 'MsFteWds'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
patheq
  • \\\\\*\\IPC$