Detection rules › Splunk
Esentutl Execution (PowerShell)
Esentutl is a command-line tool that provides database utilities for the Windows Extensible Storage Engine. This use case looks for esentutl execution or from an executable running common process command line switches used by adversaries
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth | |
| Credential Access | |
| Lateral Movement | |
| Command & Control |
References
Telemetry coverage
Rule body
id: '6147.6667'
title: Esentutl Execution
description: 'Esentutl is a command-line tool that provides database utilities for
the Windows Extensible Storage Engine. This use case looks for esentutl execution
or from an executable running common process command line switches used by adversaries.
Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN) Threat Actor Association:
Wizard Spider Software Association: Bazar, Conti, Trickbot Atomics T1003.002 Test
#3'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_powershell` (TERM(EventCode=4104) OR
"<EventID>4104<" OR TERM(EventCode=4103) OR "<EventID>4103<") ( "esentutl.exe" OR
(".exe" "/y" "/d") OR "esentutl" ) | table _time, host, user user, process, process_name
| bin span=1s | stats values(*) as * by _time, host '
techniques:
- command-and-control:ingress tool transfer
- credential-access:os credential dumping:security account manager
- credential-access:os credential dumping:ntds
- lateral-movement:lateral tool transfer
- defense-evasion:hide artifacts
technique_id:
- T1105
- T1003.002
- T1003.003
- T1570
- T1564
data_category:
- PowerShell logs
- Process command-line parameters
references:
- https://www.fireeye.com/blog/threat-research/2018/09/apt10-targeting-japanese-corporations-using-updated-ttps.html
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_powershell` (TERM(EventCode=4104) OR "<EventID>4104<" OR TERM(EventCode=4103) OR "<EventID>4103<") ( "esentutl.exe" OR (".exe" "/y" "/d") OR "esentutl" )
Stage 2: table
| table _time, host, user user, process, process_name
Stage 3: bucket
| bin span=1s
Stage 4: stats
| stats values(*) as * by _time, host
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>4104<" |
| 1 | "<EventID>4103<" |
| 1 | "esentutl.exe" |
| 1 | ".exe" |
| 1 | "/y" |
| 1 | "/d" |
| 1 | "esentutl" |