Windows Process Injection into Commonly Abused Processes

 Original Source: [splunk source]
Name:Windows Process Injection into Commonly Abused Processes
id:1e1dedc6-f6f3-41a0-9dd7-a1245904fe75
version:9
date:None
author:0xC0FFEEEE, Github Community
status:production
type:Anomaly
Description:The following analytic detects potential process injection attempts into executables that are commonly abused leveraging Sysmon EventCode 10. It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files. This activity was associated with the SliverC2 framework by BishopFox. Monitoring this activity may indicate an initial payload attempting to execute malicious code.
Data_source:
  • -Sysmon EventID 10
search:`sysmon`
EventCode=10
TargetImage IN (
"*\\backgroundtaskhost.exe",
"*\\calc.exe",
"*\\CalculatorApp.exe",
"*\\dllhost.exe",
"*\\mspaint.exe",
"*\\notepad.exe",
"*\\regsvr32.exe",
"*\\searchprotocolhost.exe",
"*\\spoolsv.exe",
"*\\svchost.exe",
"*\\werfault.exe",
"*\\win32calc.exe",
"*\\wordpad.exe",
"*\\wuauclt.exe"
)

NOT SourceImage IN (
"*:\\Windows\\Program Files (x86)\\*",
"*:\\Windows\\Program Files\\*",
"*:\\Windows\\System32\\*",
"*:\\Windows\\SysWOW64\\*"
)

```
Convert GrantedAccess from hexadecimal to decimal. The original access values represent PROCESS_DUP_HANDLE, modern full process access, and legacy full process access.
```
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_DUP_HANDLE = 64
| eval PROCESS_ALL_ACCESS = 2097151
| eval PROCESS_ALL_ACCESS_LEGACY = 2047999
| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
| eval full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS)
| eval legacy_full_access_set = bit_and(g_access_decimal, PROCESS_ALL_ACCESS_LEGACY)
| where duplicate_handle_set == PROCESS_DUP_HANDLE
OR full_access_set == PROCESS_ALL_ACCESS
OR legacy_full_access_set == PROCESS_ALL_ACCESS_LEGACY

| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product

| eval CallTrace=split(CallTrace, "|")

| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_process_injection_into_commonly_abused_processes_filter`


how_to_implement:To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives:False positives may be present based on SourceImage paths, particularly those with a legitimate reason for accessing lsass.exe or regsvr32.exe. If removing the paths is important, realize svchost and many native binaries inject into processes consistently. Restrict or tune as needed.
References:
  -https://dominicbreuker.com/post/learning_sliver_c2_08_implant_basics/
  -https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors
  -https://redcanary.com/threat-detection-report/techniques/process-injection/
drilldown_searches:
 name:'View the detection results for - "$dest$"'
 search:'%original_detection_search% | search dest = "$dest$"'
 earliest_offset:'$info_min_time$'
 latest_offset:'$info_max_time$'
 name:'View risk events for the last 7 days for - "$dest$"'
 search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
 earliest_offset:'7d'
 latest_offset:'0'
analytic_story:['BishopFox Sliver Adversary Emulation Framework', 'Earth Alux', 'SAP NetWeaver Exploitation', 'APT37 Rustonotto and FadeStealer']

asset_type:Endpoint

mitre_attack_id:['T1055.002']

product:['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']

category:endpoint

security_domain:endpoint

tags:

tests:
 name:'True Positive Test'
 attack_data:
  data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/sliver/T1055_windows-sysmon.log
  source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
  sourcetype: XmlWinEventLog
 test_type:'unit'
manual_test:None