Windows Handle Duplication in Known UAC-Bypass Binaries

 Original Source: [splunk source]
Name:Windows Handle Duplication in Known UAC-Bypass Binaries
id:d7369bf5-1315-4138-b927-2dd8bb8c1da7
version:5
date:None
author:Teoderick Contreras, Splunk
status:production
type:Anomaly
Description:The following analytic detects duplicate-handle access to known UAC-bypass binaries from a non-standard source path. It leverages Sysmon EventCode 10, converts GrantedAccess from hexadecimal, and checks for PROCESS_DUP_HANDLE.
Data_source:
  • -Sysmon EventID 10
search:`sysmon`
EventCode=10
TargetImage IN(
"*\\colorcpl.exe",
"*\\ComputerDefaults.exe",
"*\\esentutl.exe",
"*\\eventvwr.exe",
"*\\fodhelper.exe",
"*\\mmc.exe",
"*\\sdclt.exe",
"*\\slui.exe",
"*\\wsreset.exe",
"*\\PkgMgr.exe"
)
NOT SourceImage IN (
"C:\\Windows\\System32\\*",
"C:\\Windows\\SysWOW64\\*",
"C:\\Program Files\\*",
"C:\\Program Files (x86)\\*",
"%SystemRoot%\\*"
)

| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_DUP_HANDLE = 64
| eval dup_handle_set = bit_and (g_access_decimal, PROCESS_DUP_HANDLE)
| where dup_handle_set == PROCESS_DUP_HANDLE

| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product

| eval CallTrace=split(CallTrace, "|")

| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_handle_duplication_in_known_uac_bypass_binaries_filter`


how_to_implement:To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives:It is possible legitimate applications will request access to list of know abused Windows UAC binaries process, filter as needed.
References:
  -https://www.recordedfuture.com/research/from-castleloader-to-castlerat-tag-150-advances-operations
drilldown_searches:
 name:'View the detection results for - "$dest$"'
 search:'%original_detection_search% | search dest = "$dest$"'
 earliest_offset:'$info_min_time$'
 latest_offset:'$info_max_time$'
 name:'View risk events for the last 7 days for - "$dest$"'
 search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
 earliest_offset:'7d'
 latest_offset:'0'
analytic_story:['Castle RAT']

asset_type:Endpoint

mitre_attack_id:['T1134.001']

product:['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']

category:endpoint

security_domain:endpoint

tags:

tests:
 name:'True Positive Test'
 attack_data:
  data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.001/uac_process_handle_dup/Computerdefaults_access.log
  source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
  sourcetype: XmlWinEventLog
 test_type:'unit'
manual_test:None

Related Analytic Stories


Castle RAT