Rubeus Kerberos Ticket Exports Through Winlogon Access

 Original Source: [splunk source]
Name:Rubeus Kerberos Ticket Exports Through Winlogon Access
id:5ed8c50a-8869-11ec-876f-acde48001122
version:15
date:None
author:Mauricio Velazco, Splunk
status:production
type:TTP
Description:The following analytic detects an uncommon process requesting full access rights to winlogon.exe, which may indicate Rubeus exporting Kerberos tickets from memory. It leverages Sysmon EventCode 10 and checks for full-access rights, specifically the value 0x1f3fff.
Data_source:
  • -Sysmon EventID 10
search:`sysmon`
EventCode=10
TargetImage="*:\\Windows\\system32\\winlogon.exe"
NOT SourceImage IN (
"C:\\Windows\\system32\\LogonUI.exe",
"C:\\Windows\\system32\\lsass.exe",
"C:\\Windows\\system32\\smss.exe",
"C:\\Windows\\system32\\svchost.exe",
"C:\\Windows\\system32\\wbem\\wmiprvse.exe"
)

```
Convert GrantedAccess from hexadecimal to decimal. 0x1f3fff is the legacy full-access mask observed for this activity.
```
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_ALL_ACCESS_LEGACY = 2047999
| eval legacy_full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS_LEGACY)
| where legacy_full_access_set == PROCESS_ALL_ACCESS_LEGACY


| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product

| eval CallTrace=split(CallTrace, "|")

| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `rubeus_kerberos_ticket_exports_through_winlogon_access_filter`


how_to_implement:This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 10. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment.
known_false_positives:No false positives have been identified at this time.
References:
  -https://github.com/GhostPack/Rubeus
  -https://web.archive.org/web/20210725005734/http://www.harmj0y.net/blog/redteaming/from-kekeo-to-rubeus/
  -https://attack.mitre.org/techniques/T1550/003/
drilldown_searches:
 name:'View the detection results for - "$dest$"'
 search:'%original_detection_search% | search dest = "$dest$"'
 earliest_offset:'$info_min_time$'
 latest_offset:'$info_max_time$'
 name:'View risk events for the last 7 days for - "$dest$"'
 search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
 earliest_offset:'7d'
 latest_offset:'0'
analytic_story:['CISA AA23-347A', 'Active Directory Kerberos Attacks', 'BlackSuit Ransomware', 'Scattered Lapsus$ Hunters', 'ZOVWiper']

asset_type:Endpoint

mitre_attack_id:['T1550.003']

product:['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']

category:endpoint

security_domain:endpoint

tags:

tests:
 name:'True Positive Test'
 attack_data:
  data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1550.003/rubeus/windows-sysmon.log
  source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
  sourcetype: XmlWinEventLog
 test_type:'unit'
manual_test:None