Detection rules › Splunk

Potential Exposed SMB_RDP Port - Windows (Windows Event Log)

Group by
_time, host, user
Source
github.com/anvilogic-forge/armory

Threat actors may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. This use case detects successful network logon events (event 4624, Type 3) events with an external source IP, which indicates that logon events are being attempted from external IPs.

MITRE ATT&CK coverage

TacticTechniques
Initial Access

References

Telemetry coverage

Rule body

id: '28886.52418'
title: Potential Exposed SMB_RDP Port - Windows
description: Threat actors may attempt to exploit a weakness in an Internet-facing
  host or system to initially access a network. The weakness in the system can be
  a software bug, a temporary glitch, or a misconfiguration. This use case detects
  successful network logon events (event 4624, Type 3) events with an external source
  IP, which indicates that logon events are being attempted from external IPs.
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4624) OR
  "EventID>4624<") Logon_Type=3 AND NOT src_ip IN(::1, 10.0.0.0/8, 127.0.0.0/8, 172.16.0.0/12,
  192.168.0.0/16, 169.254.0.0/16, fc00::/7, fe80::/10) | iplocation src_ip prefix=geo
  | where geoCountry!=""| table _time, host, user user, process_name, process_path,
  src_country, src_dns, src_ip, geo_* | bin span=30s | stats values(*) as * by _time,
  host, user '
techniques:
- initial-access:exploit public-facing application
technique_id: 
- T1190
data_category:
- Windows event logs
references:
- https://detection.fyi/sigmahq/sigma/windows/builtin/security/account_management/win_security_successful_external_remote_smb_login/
- https://www.inversecos.com/2020/04/successful-4624-anonymous-logons-to.html

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=4624) OR "EventID>4624<") Logon_Type=3 AND NOT src_ip IN(::1, 10.0.0.0/8, 127.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, fc00::/7, fe80::/10)

Stage 2: search

| iplocation src_ip prefix=geo

Stage 3: where

| where geoCountry!=""

Stage 4: table

| table _time, host, user user, process_name, process_path, src_country, src_dns, src_ip, geo_*

Stage 5: bucket

| bin span=30s

Stage 6: stats

| stats values(*) as * by _time, host, user

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
src_ipin10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.168.0.0/16, ::1, fc00::/7, fe80::/10excludes:src_ip

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 4624 corpus 29 (splunk 13, kusto 11, chronicle 4, elastic 1)
field:"EventID" kind:eq value:"4624"
Logon_Typeeq
  • 3 corpus 41 (splunk 13, sigma 12, elastic 9, kusto 7)
field:"LogonType" kind:eq value:"3"
geoCountryne
  • ""
field:"geoCountry" kind:ne
prefixeq
  • geo corpus 2 (splunk 2)
field:"prefix" kind:eq value:"geo"

Search terms

These SPL tokens match against raw event text.

StageTerm
1"EventID>4624<"
2iplocation
2src_ip