Detection rules › Splunk

AnyDesk Command Line Execution (Sysmon)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

For most users, normal AnyDesk activity is executed via the GUI. This use case detects anydesk.exe calls from cmd.exe or PowerShell.exe. Install commands have been filtered out by default

MITRE ATT&CK coverage

TacticTechniques
Command & Control

References

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

id: '13733.20161'
title: AnyDesk Command Line Execution
description: 'For most users, normal AnyDesk activity is executed via the GUI. This
  use case detects anydesk.exe calls from cmd.exe or PowerShell.exe. Install commands
  have been filtered out by default. - Threat Actor Association: Alloy Taurus/Gallium,
  Gamaredon (aka. Armageddon, UAC-0010), Muddled Libra, Scattered Spider (aka. 0ktapus,
  UNC3944), Scatter Swine, UNC2659 - Software Association: Akira, ALPHV/BlackCat,
  AvosLocker, BianLian, BlackByte, BumbleBee, Clop, Conti, Diavol, Rhysida, Royal'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<")
  TERM(AnyDesk) (TERM(cmd) OR TERM(powershell)) | regex process!="(?i)(install)"|
  where match(process, "(?i)anydesk.exe") | table _time, host, user, process, process_*
  | bin span=1s | stats values(*) as * by _time, host '
techniques:
- command-and-control:remote access software
technique_id: 
- T1219
data_category:
- Process command-line parameters
- Windows Sysmon
references:
- https://blog.talosintelligence.com/2022/05/the-blackbyte-ransomware-group-is.html

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<") TERM(AnyDesk) (TERM(cmd) OR TERM(powershell))

Stage 2: regex

| regex process!="(?i)(install)"

Stage 3: where

| where match(process, "(?i)anydesk.exe")

Stage 4: table

| table _time, host, user, process, process_*

Stage 5: bucket

| bin span=1s

Stage 6: stats

| stats values(*) as * by _time, host

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
processregex_match"(?i)(install)"excludes:process

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 1 corpus 241 (splunk 225, kusto 15, elastic 1)
field:"EventID" kind:eq value:"1"
processregex_match
  • "(?i)anydesk.exe" corpus 2 (splunk 2)
field:"CommandLine" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>1<"
1AnyDesk
1cmd
1powershell