Detection rules › Splunk
Suspicious Spool Authentication (Windows Event Log)
It is possible to trigger RPC call using SpoolService bug, commonly found in NTLM relay attacks
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Credential Access | |
| Collection |
References
Telemetry coverage
Rule body
id: '5408.5525'
title: Suspicious Spool Authentication
description: 'It is possible to trigger RPC call using SpoolService bug, commonly
found in NTLM relay attacks. - Software Association: Ransom Cartel, Vice Society'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` ((TERM(EventCode=4624) OR
"<EventID>4624<") Authentication_Package=NTLM) OR ((TERM(EventCode=5145) OR "<EventID>5145<")
AND TERM(spoolss))| table _time, host, user signature_id, Account_Name, user, Relative_Target_Name,
signature_id, src_ip | bin span=5s | stats values(*) as * by _time, host, user |
where (match(signature_id, "(?i)4624") AND match(signature_id, "(?i)5145")) | eventstats
dc(src_ip) as dc_src_ip by host| where dc_src_ip>=1 '
techniques:
- credential-access:adversary-in-the-middle:llmnr/nbt-ns poisoning and smb relay
technique_id:
- T1557.001
data_category:
- Windows event logs
references:
- https://dirkjanm.io/a-different-way-of-abusing-zerologon/
- https://github.com/cube0x0/CVE-2021-1675
- https://securityaffairs.co/wordpress/119839/hacking/printnightmare-patch-bypass.html
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_winevent` ((TERM(EventCode=4624) OR "<EventID>4624<") Authentication_Package=NTLM) OR ((TERM(EventCode=5145) OR "<EventID>5145<") AND TERM(spoolss))
Stage 2: table
| table _time, host, user signature_id, Account_Name, user, Relative_Target_Name, signature_id, src_ip
Stage 3: bucket
| bin span=5s
Stage 4: stats
| stats values(*) as * by _time, host, user
Stage 5: where
| where (match(signature_id, "(?i)4624") AND match(signature_id, "(?i)5145"))
Stage 6: eventstats
| eventstats dc(src_ip) as dc_src_ip by host
Stage 7: where
| where dc_src_ip>=1
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
Authentication_Package | eq |
| field:"Authentication_Package" kind:eq value:"NTLM" |
EventCode | eq |
| field:"EventID" kind:eq |
dc_src_ip | ge |
| field:"dc_src_ip" kind:ge value:"1" |
signature_id | regex_match |
| field:"signature_id" kind:regex_match |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>4624<" |
| 1 | "<EventID>5145<" |
| 1 | spoolss |