Detection rules › Splunk

System Information Discovery - Windows (Sysmon)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use the information from System Information Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions

MITRE ATT&CK coverage

TacticTechniques
Discovery

References

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

id: '16900.27387'
title: System Information Discovery - Windows
description: 'An adversary may attempt to get detailed information about the operating
  system and hardware, including version, patches, hotfixes, service packs, and architecture.
  Adversaries may use the information from System Information Discovery during automated
  discovery to shape follow-on behaviors, including whether or not the adversary fully
  infects the target and/or attempts specific actions. Atomics T1082 Test #1 Atomics
  T1082 Test #6 Atomics T1082 Test #8 Atomics T1082 Test #10'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<")
  (TERM(systeminfo) OR TERM(set) OR TERM(hostname) OR (TERM(reg) TERM(query) ("HKLM\SYSTEM\CurrentControlSet"
  OR "MachineGuid"))) | regex process ="(?i)(\s+|^)(systeminfo|reg\s+query|hostname|set)(\.exe)?(\s+|$)"
  | table _time, host, user, process, process_*, parent_process* | bin span=1s | stats
  values(*) as * by _time, host '
techniques:
- discovery:system information discovery
technique_id: 
- T1082
data_category:
- Windows Sysmon
- Process command-line parameters
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1082/T1082.md

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=1) OR "<EventID>1<") (TERM(systeminfo) OR TERM(set) OR TERM(hostname) OR (TERM(reg) TERM(query) ("HKLM\SYSTEM\CurrentControlSet" OR "MachineGuid")))

Stage 2: regex

| regex process ="(?i)(\s+|^)(systeminfo|reg\s+query|hostname|set)(\.exe)?(\s+|$)"

Stage 3: table

| table _time, host, user, process, process_*, parent_process*

Stage 4: bucket

| bin span=1s

Stage 5: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 1 corpus 241 (splunk 225, kusto 15, elastic 1)
field:"EventID" kind:eq value:"1"
processregex_match
  • "(?i)(\s+|^)(systeminfo|reg\s+query|hostname|set)(.exe)?(\s+|$)" corpus 3 (splunk 3)
field:"CommandLine" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>1<"
1systeminfo
1set
1hostname
1reg
1query
1"HKLM\SYSTEM\CurrentControlSet"
1"MachineGuid"