Detection rules › Splunk
Esentutl Execution (Windows Event Log)
Esentutl is a command-line tool that provides database utilities for the Windows Extensible Storage Engine. This use case looks for esentutl execution or from an executable running common process command line switches used by adversaries
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth | |
| Credential Access | |
| Lateral Movement | |
| Command & Control |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Security-Auditing | Event ID 4688: A new process has been created. |
Rule body
id: '6147.6666'
title: Esentutl Execution
description: 'Esentutl is a command-line tool that provides database utilities for
the Windows Extensible Storage Engine. This use case looks for esentutl execution
or from an executable running common process command line switches used by adversaries.
Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN) Threat Actor Association:
Wizard Spider Software Association: Bazar, Conti, Trickbot Atomics T1003.002 Test
#3'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR
"<EventID>4688<" OR Type=Process) ( "esentutl.exe" OR (".exe" "/y" "/d") OR "esentutl"
) | regex process="(?i)(esentutl|\.exe)\"?\s.*\/y\s.*\/d\s" | table _time, host,
user, signature_id, process, process_*, parent_* | bin span=1s | stats values(*)
as * by _time, host '
techniques:
- command-and-control:ingress tool transfer
- credential-access:os credential dumping:security account manager
- credential-access:os credential dumping:ntds
- lateral-movement:lateral tool transfer
- defense-evasion:hide artifacts
technique_id:
- T1105
- T1003.002
- T1003.003
- T1570
- T1564
data_category:
- Windows event logs
- Process command-line parameters
references:
- https://www.fireeye.com/blog/threat-research/2018/09/apt10-targeting-japanese-corporations-using-updated-ttps.html
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4688) OR "<EventID>4688<" OR Type=Process) ( "esentutl.exe" OR (".exe" "/y" "/d") OR "esentutl" )
Stage 2: regex
| regex process="(?i)(esentutl|\.exe)\"?\s.*\/y\s.*\/d\s"
Stage 3: table
| table _time, host, user, signature_id, process, process_*, parent_*
Stage 4: bucket
| bin span=1s
Stage 5: stats
| stats values(*) as * by _time, host
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq value:"4688" |
process | regex_match |
| field:"CommandLine" kind:regex_match |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>4688<" |
| 1 | "esentutl.exe" |
| 1 | ".exe" |
| 1 | "/y" |
| 1 | "/d" |
| 1 | "esentutl" |