Detection rules › Splunk

Suspicious Spool Authentication (Windows Event Log)

Group by
_time, host, user
Source
github.com/anvilogic-forge/armory

It is possible to trigger RPC call using SpoolService bug, commonly found in NTLM relay attacks

MITRE ATT&CK coverage

References

Telemetry coverage

Rule body

id: '5408.5525'
title: Suspicious Spool Authentication
description: 'It is possible to trigger RPC call using SpoolService bug, commonly
  found in NTLM relay attacks. - Software Association: Ransom Cartel, Vice Society'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` ((TERM(EventCode=4624) OR
  "<EventID>4624<") Authentication_Package=NTLM) OR ((TERM(EventCode=5145) OR "<EventID>5145<")
  AND TERM(spoolss))| table _time, host, user signature_id, Account_Name, user, Relative_Target_Name,
  signature_id, src_ip | bin span=5s | stats values(*) as * by _time, host, user |
  where (match(signature_id, "(?i)4624") AND match(signature_id, "(?i)5145")) | eventstats
  dc(src_ip) as dc_src_ip by host| where dc_src_ip>=1 '
techniques:
- credential-access:adversary-in-the-middle:llmnr/nbt-ns poisoning and smb relay
technique_id:
- T1557.001
data_category:
- Windows event logs
references:
- https://dirkjanm.io/a-different-way-of-abusing-zerologon/
- https://github.com/cube0x0/CVE-2021-1675
- https://securityaffairs.co/wordpress/119839/hacking/printnightmare-patch-bypass.html

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` ((TERM(EventCode=4624) OR "<EventID>4624<") Authentication_Package=NTLM) OR ((TERM(EventCode=5145) OR "<EventID>5145<") AND TERM(spoolss))

Stage 2: table

| table _time, host, user signature_id, Account_Name, user, Relative_Target_Name, signature_id, src_ip

Stage 3: bucket

| bin span=5s

Stage 4: stats

| stats values(*) as * by _time, host, user

Stage 5: where

| where (match(signature_id, "(?i)4624") AND match(signature_id, "(?i)5145"))

Stage 6: eventstats

| eventstats dc(src_ip) as dc_src_ip by host

Stage 7: where

| where dc_src_ip>=1

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
Authentication_Packageeq
  • NTLM corpus 3 (splunk 3)
field:"Authentication_Package" kind:eq value:"NTLM"
EventCodeeq
  • 4624 corpus 29 (splunk 13, kusto 11, chronicle 4, elastic 1)
  • 5145 corpus 23 (splunk 16, elastic 5, kusto 2)
field:"EventID" kind:eq
dc_src_ipge
  • 1
field:"dc_src_ip" kind:ge value:"1"
signature_idregex_match
  • "(?i)4624" corpus 2 (splunk 2)
  • "(?i)5145" corpus 2 (splunk 2)
field:"signature_id" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>4624<"
1"<EventID>5145<"
1spoolss