Name:Windows Access Token Winlogon Duplicate Handle In Uncommon Path id:b8f7ed6b-0556-4c84-bffd-839c262b0278 version:13 date:None author:Teoderick Contreras, Splunk status:production type:Anomaly Description:The following analytic detects duplicate-handle and query-limited-information access to winlogon.exe from an uncommon or public source path.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000). Data_source:
-Sysmon EventID 10
search:`sysmon` EventCode=10 TargetImage="*:\\Windows\\System32\\winlogon.exe" NOT SourceImage IN ( "%SystemRoot%\\*", "C:\\Program Files (x86)\\*", "C:\\Program Files\\*", "C:\\Windows\\*" )
how_to_implement:To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. known_false_positives:It is possible legitimate applications will request access to winlogon, filter as needed. References: -https://docs.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-duplicatehandle -https://attack.mitre.org/techniques/T1134/001/ drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Brute Ratel C4', 'PathWiper']