Detection rules › Splunk

PromptOnSecureDesktop Registry Value Modified (PowerShell)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action. This use case detects registry modification events or process executions with registry modification commands targeting \Microsoft\Windows\CurrentVersion\Policies\System\PromptOnSecureDesktop

MITRE ATT&CK coverage

References

Telemetry coverage

Rule body

id: '31190.55838'
title: PromptOnSecureDesktop Registry Value Modified
description: 'Adversaries may bypass UAC mechanisms to elevate process privileges
  on system. Windows User Account Control (UAC) allows a program to elevate its privileges
  (tracked as integrity levels ranging from low to high) to perform a task under administrator-level
  permissions, possibly by prompting the user for confirmation. The impact to the
  user ranges from denying the operation under high enforcement to allowing the user
  to perform the action if they are in the local administrators group and click through
  the prompt or allowing them to enter an administrator password to complete the action.
  This use case detects registry modification events or process executions with registry
  modification commands targeting \Microsoft\Windows\CurrentVersion\Policies\System\PromptOnSecureDesktop.
  -- Software Association: 8Base'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_powershell` (TERM(EventCode=4103) OR
  "<EventID>4103<" OR TERM(EventCode=4104) OR "<EventID>4104<") ("Set-Item-Property"
  OR "sp " OR "ADD") "PromptOnSecureDesktop" "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System"
  | table _time, host, user, process | bin span=1s | stats values(*) as * by _time,
  host '
techniques:
- privilege-escalation:abuse elevation control mechanism:bypass user account control
technique_id:
- T1548.002
data_category:
- PowerShell logs
references:
- https://attack.mitre.org/techniques/T1548/002/
- https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-8base?utm_source=trendmicroresearch&utm_medium=smk&utm_campaign=0424_8base
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_powershell` (TERM(EventCode=4103) OR "<EventID>4103<" OR TERM(EventCode=4104) OR "<EventID>4104<") ("Set-Item-Property" OR "sp " OR "ADD") "PromptOnSecureDesktop" "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System"

Stage 2: table

| table _time, host, user, process

Stage 3: bucket

| bin span=1s

Stage 4: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 4103 corpus 105 (splunk 105)
  • 4104 corpus 269 (splunk 269)
field:"EventID" kind:eq

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>4103<"
1"<EventID>4104<"
1"Set-Item-Property"
1"sp "
1"ADD"
1"PromptOnSecureDesktop"
1"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System"