Detection rules › Splunk

AnyDesk Command Line Execution (Windows Event Log)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

For most users, normal AnyDesk activity is executed via the GUI. This use case detects anydesk.exe calls from cmd.exe or PowerShell.exe. Install commands have been filtered out by default

MITRE ATT&CK coverage

TacticTechniques
Command & Control

References

Telemetry coverage

Rule body

id: '13733.20159'
title: AnyDesk Command Line Execution
description: 'For most users, normal AnyDesk activity is executed via the GUI. This
  use case detects anydesk.exe calls from cmd.exe or PowerShell.exe. Install commands
  have been filtered out by default. - Threat Actor Association: Alloy Taurus/Gallium,
  Gamaredon (aka. Armageddon, UAC-0010), Muddled Libra, Scattered Spider (aka. 0ktapus,
  UNC3944), Scatter Swine, UNC2659 - Software Association: Akira, ALPHV/BlackCat,
  AvosLocker, BianLian, BlackByte, BumbleBee, Clop, Conti, Diavol, Rhysida, Royal'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR
  "<EventID>4688<" OR Type=Process) TERM(AnyDesk) (TERM(cmd) OR TERM(powershell))
  | regex process!="(?i)(install)"| where match(process, "(?i)anydesk.exe") | table
  _time, host, user, process, process_* | bin span=1s | stats values(*) as * by _time,
  host '
techniques:
- command-and-control:remote access software
technique_id: 
- T1219
data_category:
- Windows event logs
- Process command-line parameters
references:
- https://blog.talosintelligence.com/2022/05/the-blackbyte-ransomware-group-is.html

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR "<EventID>4688<" OR Type=Process) TERM(AnyDesk) (TERM(cmd) OR TERM(powershell))

Stage 2: regex

| regex process!="(?i)(install)"

Stage 3: where

| where match(process, "(?i)anydesk.exe")

Stage 4: table

| table _time, host, user, process, process_*

Stage 5: bucket

| bin span=1s

Stage 6: stats

| stats values(*) as * by _time, host

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
processregex_match"(?i)(install)"excludes:process

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 4688 corpus 317 (splunk 283, kusto 33, elastic 1)
field:"EventID" kind:eq value:"4688"
processregex_match
  • "(?i)anydesk.exe" corpus 2 (splunk 2)
field:"CommandLine" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>4688<"
1AnyDesk
1cmd
1powershell