From 56357ceb1de5b60ca6858ea8c46258ca82a974ff Mon Sep 17 00:00:00 2001 From: onurmerdogan Date: Wed, 23 Sep 2026 16:39:29 +0200 Subject: [PATCH 01/10] New Approach on Handling Renamed Binaries --- .../detect_html_help_renamed.yml | 16 +- .../detect_mshta_renamed.yml | 16 +- .../detect_renamed_7_zip.yml | 16 +- .../detect_renamed_psexec.yml | 16 +- .../detect_renamed_rclone.yml | 16 +- .../detect_renamed_winrar.yml | 16 +- ...ous_microsoft_workflow_compiler_rename.yml | 16 +- .../suspicious_msbuild_rename.yml | 16 +- .../windows_regsvr32_renamed_binary.yml | 16 +- .../windows_renamed_powershell_execution.yml | 16 +- ...indows_lolbas_executed_as_renamed_file.yml | 65 -------- ...named_command_interpreter_was_executed.yml | 97 ++++++++++++ ...ows_renamed_lolbas_binary_was_executed.yml | 96 ++++++++++++ ...opular_3rd_party_software_was_executed.yml | 94 +++++++++++ ...ows_renamed_python_binary_was_executed.yml | 86 ++++++++++ lookups/csv/renamed_lolbas_binaries.csv | 147 ++++++++++++++++++ lookups/csv/renamed_lolbas_binaries.yml | 14 ++ .../renamed_popular_3rd_party_binaries.csv | 43 +++++ .../renamed_popular_3rd_party_binaries.yml | 14 ++ ...d_windows_command_interpreter_binaries.csv | 13 ++ ...d_windows_command_interpreter_binaries.yml | 14 ++ 21 files changed, 688 insertions(+), 155 deletions(-) rename detections/{endpoint => deprecated}/detect_html_help_renamed.yml (88%) rename detections/{endpoint => deprecated}/detect_mshta_renamed.yml (88%) rename detections/{endpoint => deprecated}/detect_renamed_7_zip.yml (87%) rename detections/{endpoint => deprecated}/detect_renamed_psexec.yml (89%) rename detections/{endpoint => deprecated}/detect_renamed_rclone.yml (88%) rename detections/{endpoint => deprecated}/detect_renamed_winrar.yml (87%) rename detections/{endpoint => deprecated}/suspicious_microsoft_workflow_compiler_rename.yml (89%) rename detections/{endpoint => deprecated}/suspicious_msbuild_rename.yml (89%) rename detections/{endpoint => deprecated}/windows_regsvr32_renamed_binary.yml (90%) rename detections/{endpoint => deprecated}/windows_renamed_powershell_execution.yml (90%) delete mode 100644 detections/endpoint/windows_lolbas_executed_as_renamed_file.yml create mode 100644 detections/endpoint/windows_renamed_command_interpreter_was_executed.yml create mode 100644 detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml create mode 100644 detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml create mode 100644 detections/endpoint/windows_renamed_python_binary_was_executed.yml create mode 100644 lookups/csv/renamed_lolbas_binaries.csv create mode 100644 lookups/csv/renamed_lolbas_binaries.yml create mode 100644 lookups/csv/renamed_popular_3rd_party_binaries.csv create mode 100644 lookups/csv/renamed_popular_3rd_party_binaries.yml create mode 100644 lookups/csv/renamed_windows_command_interpreter_binaries.csv create mode 100644 lookups/csv/renamed_windows_command_interpreter_binaries.yml diff --git a/detections/endpoint/detect_html_help_renamed.yml b/detections/deprecated/detect_html_help_renamed.yml similarity index 88% rename from detections/endpoint/detect_html_help_renamed.yml rename to detections/deprecated/detect_html_help_renamed.yml index e9d228305a9..2dcbeaf831c 100644 --- a/detections/endpoint/detect_html_help_renamed.yml +++ b/detections/deprecated/detect_html_help_renamed.yml @@ -2,9 +2,9 @@ name: Detect HTML Help Renamed id: 62fed254-513b-460e-953d-79771493a9f3 version: 14 creation_date: '2021-02-11' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects instances where hh.exe (HTML Help) has been renamed and is executing a Compiled HTML Help (CHM) file. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names. This activity is significant because attackers can use renamed hh.exe to execute malicious scripts embedded in CHM files, potentially leading to code execution. If confirmed malicious, this technique could allow attackers to run arbitrary scripts, escalate privileges, or persist within the environment, posing a significant security risk. data_source: @@ -46,10 +46,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/deprecated/detect_mshta_renamed.yml similarity index 88% rename from detections/endpoint/detect_mshta_renamed.yml rename to detections/deprecated/detect_mshta_renamed.yml index e04f4d7434c..2587d9a661c 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/deprecated/detect_mshta_renamed.yml @@ -2,9 +2,9 @@ name: Detect mshta renamed id: 8f45fcf0-5b68-11eb-ae93-0242ac130002 version: 13 creation_date: '2021-01-15' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic identifies instances where mshta.exe has been renamed and executed. It leverages Endpoint Detection and Response (EDR) data, specifically focusing on the original file name field to detect discrepancies. This activity is significant because renaming mshta.exe is a common tactic used by attackers to evade detection and execute malicious scripts. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. data_source: @@ -45,10 +45,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/detect_renamed_7_zip.yml b/detections/deprecated/detect_renamed_7_zip.yml similarity index 87% rename from detections/endpoint/detect_renamed_7_zip.yml rename to detections/deprecated/detect_renamed_7_zip.yml index 667a8ad2f50..1abebcc1f15 100644 --- a/detections/endpoint/detect_renamed_7_zip.yml +++ b/detections/deprecated/detect_renamed_7_zip.yml @@ -2,9 +2,9 @@ name: Detect Renamed 7-Zip id: 4057291a-b8cf-11eb-95fe-acde48001122 version: 12 creation_date: '2021-06-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the usage of a renamed 7-Zip executable using Sysmon data. It leverages the OriginalFileName field to identify instances where the 7-Zip process has been renamed. This activity is significant as attackers often rename legitimate tools to evade detection while staging or exfiltrating data. If confirmed malicious, this behavior could indicate data exfiltration attempts or other unauthorized data manipulation, potentially leading to significant data breaches or loss of sensitive information. Analysts should validate the legitimacy of the 7-Zip executable and investigate parallel processes for further suspicious activities. data_source: @@ -45,10 +45,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/deprecated/detect_renamed_psexec.yml similarity index 89% rename from detections/endpoint/detect_renamed_psexec.yml rename to detections/deprecated/detect_renamed_psexec.yml index 2e56a883799..b201e36bffd 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/deprecated/detect_renamed_psexec.yml @@ -2,9 +2,9 @@ name: Detect Renamed PSExec id: 683e6196-b8e8-11eb-9a79-acde48001122 version: 17 creation_date: '2021-06-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk, Alex Oberkircher, Github Community -status: production +status: deprecated type: Hunting description: The following analytic identifies instances where `PsExec.exe` has been renamed and executed on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names. This activity is significant because renaming `PsExec.exe` is a common tactic to evade detection. If confirmed malicious, this could allow an attacker to execute commands remotely, potentially leading to unauthorized access, lateral movement, or further compromise of the network. data_source: @@ -60,10 +60,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed Command Interpreter was Executed diff --git a/detections/endpoint/detect_renamed_rclone.yml b/detections/deprecated/detect_renamed_rclone.yml similarity index 88% rename from detections/endpoint/detect_renamed_rclone.yml rename to detections/deprecated/detect_renamed_rclone.yml index d7bbfa5d717..cf1b820632c 100644 --- a/detections/endpoint/detect_renamed_rclone.yml +++ b/detections/deprecated/detect_renamed_rclone.yml @@ -2,9 +2,9 @@ name: Detect Renamed RClone id: 6dca1124-b3ec-11eb-9328-acde48001122 version: 12 creation_date: '2021-05-13' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the execution of a renamed `rclone.exe` process, which is commonly used for data exfiltration to remote destinations. This detection leverages Endpoint Detection and Response (EDR) telemetry, focusing on process names and original file names that do not match. This activity is significant because ransomware groups often use RClone to exfiltrate sensitive data. If confirmed malicious, this behavior could indicate an ongoing data exfiltration attempt, potentially leading to significant data loss and further compromise of the affected systems. data_source: @@ -49,10 +49,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/endpoint/detect_renamed_winrar.yml b/detections/deprecated/detect_renamed_winrar.yml similarity index 87% rename from detections/endpoint/detect_renamed_winrar.yml rename to detections/deprecated/detect_renamed_winrar.yml index 5779de2a81b..58651d38fcf 100644 --- a/detections/endpoint/detect_renamed_winrar.yml +++ b/detections/deprecated/detect_renamed_winrar.yml @@ -2,9 +2,9 @@ name: Detect Renamed WinRAR id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 version: 16 creation_date: '2021-06-03' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic identifies instances where `WinRAR.exe` has been renamed and executed. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names within the Endpoint data model. This activity is significant because renaming executables is a common tactic used by attackers to evade detection. If confirmed malicious, this could indicate an attempt to bypass security controls, potentially leading to unauthorized data extraction or further system compromise. data_source: @@ -45,10 +45,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml similarity index 89% rename from detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml rename to detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml index 21f34aefa8a..061234295d4 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml @@ -2,9 +2,9 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 version: 14 creation_date: '2021-01-19' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the renaming of microsoft.workflow.compiler.exe, a rarely used executable typically located in C:\Windows\Microsoft.NET\Framework64\v4.0.30319. This detection leverages Endpoint Detection and Response (EDR) data, focusing on process names and original file names. This activity is significant because renaming this executable can indicate an attempt to evade security controls. If confirmed malicious, an attacker could use this renamed executable to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment. data_source: @@ -49,10 +49,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/deprecated/suspicious_msbuild_rename.yml similarity index 89% rename from detections/endpoint/suspicious_msbuild_rename.yml rename to detections/deprecated/suspicious_msbuild_rename.yml index 7a4091f3103..6d8edfa66d2 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/deprecated/suspicious_msbuild_rename.yml @@ -2,9 +2,9 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 version: 14 creation_date: '2021-01-15' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Michael Haag, Splunk -status: production +status: deprecated type: Hunting description: The following analytic detects the execution of renamed instances of msbuild.exe. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names within the Endpoint data model. This activity is significant because msbuild.exe is a legitimate tool often abused by attackers to execute malicious code while evading detection. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network. data_source: @@ -51,10 +51,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/windows_regsvr32_renamed_binary.yml b/detections/deprecated/windows_regsvr32_renamed_binary.yml similarity index 90% rename from detections/endpoint/windows_regsvr32_renamed_binary.yml rename to detections/deprecated/windows_regsvr32_renamed_binary.yml index 883a47c7e4b..f36818f47b9 100644 --- a/detections/endpoint/windows_regsvr32_renamed_binary.yml +++ b/detections/deprecated/windows_regsvr32_renamed_binary.yml @@ -2,9 +2,9 @@ name: Windows Regsvr32 Renamed Binary id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a version: 13 creation_date: '2022-10-27' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Teoderick Contreras, Splunk -status: production +status: deprecated type: TTP description: The following analytic identifies instances where the regsvr32.exe binary has been renamed and executed. This detection leverages Endpoint Detection and Response (EDR) data, specifically focusing on the original filename metadata. Renaming regsvr32.exe is significant as it can be an evasion technique used by attackers to bypass security controls. If confirmed malicious, this activity could allow an attacker to execute arbitrary DLLs, potentially leading to code execution, privilege escalation, or persistence within the environment. data_source: @@ -58,10 +58,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_3/sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/endpoint/windows_renamed_powershell_execution.yml b/detections/deprecated/windows_renamed_powershell_execution.yml similarity index 90% rename from detections/endpoint/windows_renamed_powershell_execution.yml rename to detections/deprecated/windows_renamed_powershell_execution.yml index bade4e80afd..3ff0b4be4c2 100644 --- a/detections/endpoint/windows_renamed_powershell_execution.yml +++ b/detections/deprecated/windows_renamed_powershell_execution.yml @@ -2,9 +2,9 @@ name: Windows Renamed Powershell Execution id: c08014de-cc5a-42de-9775-76ecd5b37bbd version: 8 creation_date: '2022-10-27' -modification_date: '2026-05-13' +modification_date: '2026-09-23' author: Teoderick Contreras, Nasreddine Bencherchali, Splunk -status: production +status: deprecated type: TTP description: The following analytic identifies instances where the PowerShell executable has been renamed and executed under an alternate filename. This behavior is commonly associated with attempts to evade security controls or bypass logging mechanisms that monitor standard PowerShell usage. While rare in legitimate environments, renamed PowerShell binaries are frequently observed in malicious campaigns leveraging Living-off-the-Land Binaries (LOLBins) and fileless malware techniques. This detection flags executions of PowerShell where the process name does not match the default powershell.exe or pwsh.exe, especially when invoked from unusual paths or accompanied by suspicious command-line arguments. data_source: @@ -42,10 +42,8 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_powershell/renamed_powershell.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit +deprecation_info: + reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed Command Interpreter was Executed diff --git a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml b/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml deleted file mode 100644 index de0367bd262..00000000000 --- a/detections/endpoint/windows_lolbas_executed_as_renamed_file.yml +++ /dev/null @@ -1,65 +0,0 @@ -name: Windows LOLBAS Executed As Renamed File -id: fd496996-7d9e-4894-8d40-bb85b6192dc6 -version: 10 -creation_date: '2024-05-03' -modification_date: '2026-05-13' -author: Steven Dick -status: production -type: TTP -description: The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. -data_source: - - Sysmon EventID 1 - - Windows Event Log Security 4688 - - CrowdStrike ProcessRollup2 -search: '| tstats `security_content_summariesonly` latest(Processes.parent_process) as parent_process, latest(Processes.process) as process, latest(Processes.process_guid) as process_guid count, min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where NOT Processes.original_file_name IN("-","unknown") AND NOT Processes.process_path IN ("*\\Program Files*","*\\PROGRA~*","*\\Windows\\System32\\*","*\\Windows\\Syswow64\\*") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product |`drop_dm_object_name(Processes)` | where NOT match(process_name, "(?i)".original_file_name) | lookup lolbas_file_path lolbas_file_name as original_file_name OUTPUT description as desc | search desc!="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_lolbas_executed_as_renamed_file_filter`' -how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: A certain amount of false positives are likely with this detection. MSI based installers often trigger for SETUPAPL.dll and vendors will often copy system exectables to a different path for application usage. -references: - - https://attack.mitre.org/techniques/T1036/ - - https://attack.mitre.org/techniques/T1036/003/ -drilldown_searches: - - name: View the detection results for - "$dest$" and "$user$" - search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' - earliest_offset: $info_min_time$ - latest_offset: $info_max_time$ - - name: View risk events for the last 7 days for - "$dest$" and "$user$" - search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' - earliest_offset: 7d - latest_offset: "0" -finding: - title: The file originally named $original_file_name$ was executed as $process_name$ on $dest$ - entity: - field: user - type: user - score: 50 -intermediate_findings: - entities: - - field: dest - type: system - score: 50 - message: The file originally named $original_file_name$ was executed as $process_name$ on $dest$ -threat_objects: - - field: process_name - type: process_name -analytic_story: - - Living Off The Land - - Masquerading - Rename System Utilities - - Windows Defense Evasion Tactics - - Water Gamayun -asset_type: Endpoint -mitre_attack_id: - - T1036.003 - - T1218.011 -product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud -category: endpoint -security_domain: endpoint -tests: - - name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/cmd_lolbas_usage/cmd_lolbas_usage.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: XmlWinEventLog - test_type: unit diff --git a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml new file mode 100644 index 00000000000..469db2e44e9 --- /dev/null +++ b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml @@ -0,0 +1,97 @@ +name: Windows Renamed Command Interpreter was Executed +id: 6f4611be-076e-4fa8-bc78-466588a71442 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a Windows command interpreter process being executed where it's process + name does not match it's original file name attribute. Processes that have been renamed and executed may + be an indicator that an adversary is attempting to evade defenses or execute malicious code. +data_source: + - Sysmon EventID 1 + - Windows Event Log Security 4688 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime + FROM datamodel=Endpoint.Processes + WHERE + NOT Processes.original_file_name IN ("-","unknown") + AND [ + | inputlookup renamed_windows_command_interpreter_binaries.csv + | rename original_file_name as Processes.original_file_name + | table Processes.original_file_name + ] + AND NOT [ + | inputlookup renamed_windows_command_interpreter_binaries.csv + | rename original_file_name as Processes.process_name + | table Processes.process_name + ] + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec + Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id + Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) + | where NOT match(process_name, "(?i)".original_file_name) + | lookup renamed_windows_command_interpreter_binaries original_file_name OUTPUT description + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_command_interpreter_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: 3rd party software binaries sharing the same name as Windows command interpreter binaries may trigger false positives. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ + - https://attack.mitre.org/techniques/T1059/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 30 + message: Command Interpreter [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] +threat_objects: + - field: process_name + type: process_name +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Suspicious Command-Line Executions + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 + - T1059 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_command_interpreter/renamed_command_interpreter.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml new file mode 100644 index 00000000000..17dfc7c5ffa --- /dev/null +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -0,0 +1,96 @@ +name: Windows Renamed LOLBAS Binary was Executed +id: fd496996-7d9e-4894-8d40-bb85b6192dc6 +version: 11 +creation_date: '2024-05-03' +modification_date: '2026-09-23' +author: Steven Dick, Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a LOLBAS process being executed where it's process name does not match + it's original file name attribute. Processes that have been renamed and executed may be an indicator that + an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows + native binaries that can be abused by threat actors to perform tasks like executing malicious code. +data_source: + - Sysmon EventID 1 + - Windows Event Log Security 4688 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime + FROM datamodel=Endpoint.Processes + WHERE + NOT Processes.original_file_name IN ("-","unknown") + AND [ + | inputlookup renamed_lolbas_binaries.csv + | rename original_file_name as Processes.original_file_name + | table Processes.original_file_name + ] + AND NOT [ + | inputlookup renamed_lolbas_binaries.csv + | rename original_file_name as Processes.process_name + | table Processes.process_name + ] + AND NOT process_name IN ('excelcnv.exe', 'installutil64.exe', 'protoc~1.exe', 'regwrite.exe', 'vzshadow.exe') + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec + Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id + Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) + | where NOT match(process_name, "(?i)".original_file_name) + | lookup renamed_lolbas_binaries original_file_name OUTPUT description + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_lolbas_binary_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: 3rd party software binaries sharing the same name as LOLBAS utilities may trigger false positives. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 30 + message: LOLBAS utility [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] +threat_objects: + - field: process_name + type: process_name +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/cmd_lolbas_usage/cmd_lolbas_usage.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml new file mode 100644 index 00000000000..a16a53e5051 --- /dev/null +++ b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml @@ -0,0 +1,94 @@ +name: Windows Renamed Popular 3rd Party Software was Executed +id: cf6713c7-ac6b-4963-83a6-39f24ed10aa8 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a popular 3rd party software process being executed where it's process name + does not match it's original file name attribute. Processes that have been renamed and executed may be an + indicator that an adversary is attempting to evade defenses or execute malicious code. +data_source: + - Sysmon EventID 1 + - Windows Event Log Security 4688 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime + FROM datamodel=Endpoint.Processes + WHERE + NOT Processes.original_file_name IN ("-","unknown") + AND [ + | inputlookup renamed_popular_3rd_party_binaries.csv + | rename original_file_name as Processes.original_file_name + | table Processes.original_file_name + ] + AND NOT [ + | inputlookup renamed_popular_3rd_party_binaries.csv + | rename original_file_name as Processes.process_name + | table Processes.process_name + ] + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec + Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id + Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) + | where NOT match(process_name, "(?i)".original_file_name) + | lookup renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_popular_3rd_party_software_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: 3rd party software binaries might have overlapping executable names. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 30 + message: Windows 3rd Party software [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] +threat_objects: + - field: process_name + type: process_name +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_3rd_party_software/renamed_3rd_party_software.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/detections/endpoint/windows_renamed_python_binary_was_executed.yml b/detections/endpoint/windows_renamed_python_binary_was_executed.yml new file mode 100644 index 00000000000..baeb6163d38 --- /dev/null +++ b/detections/endpoint/windows_renamed_python_binary_was_executed.yml @@ -0,0 +1,86 @@ +name: Windows Renamed Python Binary was Executed +id: 6735153f-2da0-4eba-a428-288898613837 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Onur Mustafa Erdogan, Splunk +status: production +type: Anomaly +description: |- + The following analytic identifies a Python process being executed where it's process name does not match + it's original file name attribute. Processes that have been renamed and executed may be an indicator that + an adversary is attempting to evade defenses or execute malicious code. +data_source: + - Sysmon EventID 1 + - Windows Event Log Security 4688 + - CrowdStrike ProcessRollup2 +search: |- + | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime + FROM datamodel=Endpoint.Processes + WHERE + NOT Processes.original_file_name IN ("-","unknown") + NOT Processes.process_name IN ("dwagent.exe", "WinUtils.exe") + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec + Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id + Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | regex original_file_name="(?i)^(?:py|pyw|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+)\.exe$" + | regex process_name="(?i)^(?:py|pyw|pip|pip3|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+|pip3\.\w+|idle3\.\w+)\.exe$" + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_renamed_python_binary_was_executed_filter` +how_to_implement: |- + The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents + are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement + this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, + you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk + Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node + of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and + speed up the data modeling process. +known_false_positives: Various Python implementations might have a different executable name, which could trigger false positives. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ + - https://attack.mitre.org/techniques/T1059/006/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +intermediate_findings: + entities: + - field: dest + type: system + score: 30 + message: Python binary [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] +threat_objects: + - field: process_name + type: process_name +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 + - T1059.006 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_python_binary/renamed_python_binary.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit diff --git a/lookups/csv/renamed_lolbas_binaries.csv b/lookups/csv/renamed_lolbas_binaries.csv new file mode 100644 index 00000000000..ba83e577f1f --- /dev/null +++ b/lookups/csv/renamed_lolbas_binaries.csv @@ -0,0 +1,147 @@ +original_file_name,description +acccheckconsole.exe,Verifies UI accessibility requirements +addinutil.exe,.NET Tool used for updating cache files for Microsoft Office Add-Ins. +adplus.exe,Debugging tool included with Windows Debugging Tools +agentexecutor.exe,Intune Management Extension included on Intune Managed Devices +appcert.exe,Windows App Certification Kit command-line tool. +appinstaller.exe,Tool used for installation of AppX/MSIX applications on Windows 10 +appvlp.exe,Application Virtualization Utility Included with Microsoft Office 2016 +aspnet_compiler.exe,ASP.NET Compilation Tool +at.exe,Schedule periodic tasks +atbroker.exe,Helper binary for Assistive Technology (AT) +bitsadmin.exe,Used for managing background intelligent transfer +cdb.exe,Debugging tool included with Windows Debugging Tools. +certoc.exe,Used for installing certificates +certreq.exe,Used for requesting and managing certificates +certutil.exe,Windows binary used for handling certificates +cmdkey.exe,"creates, lists, and deletes stored user names and passwords or credentials." +cmdl32.exe,Microsoft Connection Manager Auto-Download +cmstp.exe,Installs or removes a Connection Manager service profile. +colorcpl.exe,Binary that handles color management +conhost.exe,Console Window host +control.exe,Console Window host +csc.exe,Binary file used by .NET to compile C# code +cscript.exe,Binary used to execute scripts in Windows +csi.exe,Command line interface included with Visual Studio. +curl.exe,Used for transferring data to or from a server; bundled with Windows 10 1803+ and can be used to download or upload files (not in repo lookup - added manually) +customshellhost.exe,A host process that is used by custom shells when using Windows in Kiosk mode. +datasvcutil.exe,DataSvcUtil.exe is a command-line tool provided by WCF Data Services that consumes an Open Data Protocol (OData) feed and generates the client data service classes that are needed to access a data service from a .NET Framework client application. +desktopimgdownldr.exe,Windows binary used to configure lockscreen/desktop image +devicecredentialdeployment.exe,Device Credential Deployment +devinit.exe,Visual Studio 2019 tool +devtoolslauncher.exe,Binary will execute specified binary. Part of VS/VScode installation. +dfsvc.exe,ClickOnce engine in Windows used by .NET +diantz.exe,Binary that package existing files into a cabinet (.cab) file +diskshadow.exe,Diskshadow.exe is a tool that exposes the functionality offered by the volume shadow copy Service (VSS). +dnscmd.exe,A command-line interface for managing DNS servers +dotnet.exe,dotnet.exe comes with .NET Framework +dsdbutil.exe,Dsdbutil is a command-line tool that is built into Windows Server. It is available if you have the AD LDS server role installed. Can be used as a command line utility to export Active Directory. +dumpminitool.exe,Dump tool part Visual Studio 2022 +dxcap.exe,DirectX diagnostics/debugger included with Visual Studio. +esentutl.exe,Binary for working with Microsoft Joint Engine Technology (JET) database +eventvwr.exe,Displays Windows Event Logs in a GUI window. +excel.exe,Microsoft Office binary +expand.exe,Binary that expands one or more compressed files +extexport.exe,Load a DLL located in the C:\test folder with a specific name. +extrac32.exe,"Extract to ADS, copy or overwrite a file with Extrac32.exe" +findstr.exe,"Write to ADS, discover, or download files with Findstr.exe" +finger.exe,Displays information about a user or users on a specified remote computer that is running the Finger service or daemon +fltmc.exe,Filter Manager Control Program used by Windows +forfiles.exe,Selects and executes a command on a file or set of files. This command is useful for batch processing. +fsi.exe,64-bit FSharp (F#) Interpreter included with Visual Studio and DotNet Core SDK. +fsianycpu.exe,32/64-bit FSharp (F#) Interpreter included with Visual Studio. +fsutil.exe,File System Utility +ftp.exe,A binary designed for connecting to FTP servers +gfxdownloadwrapper.exe,"Remote file download used by the Intel Graphics Control Panel, receives as first parameter a URL and a destination file path." +gpscript.exe,Used by group policy to process scripts +hh.exe,Binary used for processing chm files in Windows +ie4uinit.exe,Executes commands from a specially prepared ie4uinit.inf file. +iediagcmd.exe,Diagnostics Utility for Internet Explorer +ieexec.exe,The IEExec.exe application is an undocumented Microsoft .NET Framework application that is included with the .NET Framework. You can use the IEExec.exe application as a host to run other managed applications that you start by using a URL. +ilasm.exe,used for compile c# code into dll or exe. +imewdbld.exe,Microsoft IME Open Extended Dictionary Module +infdefaultinstall.exe,Binary used to perform installation based on content inside inf files +installutil.exe,The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies +jsc.exe,Binary file used by .NET to compile javascript code to .exe or .dll format +ldifde.exe,"Creates, modifies, and deletes LDAP directory objects." +makecab.exe,Binary to package existing files into a cabinet (.cab) file +manage-bde.wsf,Script for managing BitLocker +mavinject.exe,Used by App-v in Windows +mftrace.exe,Trace log generation tool for Media Foundation Tools. +microsoft.nodejstools.pressanykey.exe,Part of the NodeJS Visual Studio tools. +microsoft.workflow.compiler.exe,A utility included with .NET that is capable of compiling and executing C# or VB.net code. +mmc.exe,Load snap-ins to locally and remotely manage Windows systems +msaccess.exe,Microsoft Office binary +msbuild.exe,Used to compile and execute code +msconfig.exe,"MSConfig is a troubleshooting tool which is used to temporarily disable or re-enable software, device drivers or Windows services that run during startup process to help the user determine the cause of a problem with Windows" +msdeploy.exe,Microsoft tool used to deploy Web Applications. +msdt.exe,Microsoft diagnostics tool +mshta.exe,Used by Windows to execute html applications. (.hta) +msiexec.exe,Used by Windows to execute msi files +msohtmed.exe,Microsoft Office binary +mspub.exe,Microsoft Office binary +netsh.exe,Netsh is a Windows tool used to manipulate network interface settings. +ntdsutil.exe,Command line utility used to export Active Directory. +odbcconf.exe,Used in Windows for managing ODBC connections +offlinescannershell.exe,Windows Defender Offline Shell +pcalua.exe,Program Compatibility Assistant +pcwrun.exe,Program Compatibility Wizard +pktmon.exe,Capture Network Packets on the windows 10 with October 2018 Update or later. +pnputil.exe,Used for installing drivers +powerpnt.exe,Microsoft Office binary +presentationhost.exe,File is used for executing Browser applications +print.exe,Used by Windows to send files to the printer +printbrm.exe,Printer Migration Command-Line Tool +protocolhandler.exe,Microsoft Office binary +provlaunch.exe,Launcher process +psr.exe,"Windows Problem Steps Recorder, used to record screen and clicks." +rasautou.exe,Windows Remote Access Dialer +rdrleakdiag.exe,Microsoft Windows resource leak diagnostic tool +reg.exe,Used to manipulate the registry +regasm.exe,Part of .NET +regedit.exe,Used by Windows to manipulate registry +regini.exe,Used to manipulate the registry +register-cimprovider.exe,Used to register new wmi providers +regsvcs.exe,Regsvcs and Regasm are Windows command-line utilities that are used to register .NET Component Object Model (COM) assemblies +regsvr32.exe,Used by Windows to register dlls +replace.exe,Used to replace file with another file +rpcping.exe,Used to verify rpc connection +rundll32.exe,Used by Windows to execute dll files +runexehelper.exe,Launcher process +runonce.exe,Executes a Run Once Task that has been configured in the registry +sc.exe,Used by Windows to manage services +schtasks.exe,Schedule periodic tasks +scriptrunner.exe,Execute binary through proxy binary to evade defensive counter measures +setres.exe,Configures display settings +settingsynchost.exe,Host Process for Setting Synchronization +sqldumper.exe,Debugging utility included with Microsoft SQL. +sqlps.exe,"Tool included with Microsoft SQL Server that loads SQL Server cmdlets. Microsoft SQL Server\100 and 110 are Powershell v2. Microsoft SQL Server\120 and 130 are Powershell version 4. Replaced by SQLToolsPS.exe in SQL Server 2016, but will be included with installation for compatability reasons." +sqltoolsps.exe,Tool included with Microsoft SQL that loads SQL Server cmdlts. A replacement for sqlps.exe. Successor to sqlps.exe in SQL Server 2016+. +stordiag.exe,Storage diagnostic tool +syncappvpublishingserver.exe,Used by App-v to get App-v server lists +tar.exe,Used by Windows to extract and create archives. +testwindowremoteagent.exe,TestWindowRemoteAgent.exe is the command-line tool to establish RPC +ttdinject.exe,Used by Windows 1809 and newer to Debug Time Travel (Underlying call of tttracer.exe) +tttracer.exe,Used by Windows 1809 and newer to Debug Time Travel +unregmp2.exe,Microsoft Windows Media Player Setup Utility +vbc.exe,Binary file used for compile vbs code +verclsid.exe,Used to verify a COM object before it is instantiated by Windows Explorer +visualuiaverifynative.exe,A Windows SDK binary for manual and automated testing of Microsoft UI Automation implementation and controls. +vsdiagnostics.exe,Command-line tool used for performing diagnostics. +vshadow.exe,VShadow is a command-line tool that can be used to create and manage volume shadow copies. +vsiisexelauncher.exe,Binary will execute specified binary. Part of VS/VScode installation. +vsjitdebugger.exe,Just-In-Time (JIT) debugger included with Visual Studio +vsls-agent.exe,Agent for Visual Studio Live Share (Code Collaboration) +vstest.console.exe,VSTest.Console.exe is the command-line tool to run tests +wab.exe,Windows address book manager +wbadmin.exe,Windows Backup Administration utility +wfc.exe,The Workflow Command-line Compiler tool is included with the Windows Software Development Kit (SDK). +winproj.exe,Microsoft Project Executable +winword.exe,Microsoft Office binary +wlrmdr.exe,Windows Logon Reminder executable +wmic.exe,The WMI command-line (WMIC) utility provides a command-line interface for WMI +workfolders.exe,Work Folders +wscript.exe,Used by Windows to execute scripts +wsreset.exe,Used to reset Windows Store settings according to its manifest file +wuauclt.exe,Windows Update Client +xwizard.exe,Execute custom class that has been added to the registry or download a file with Xwizard.exe diff --git a/lookups/csv/renamed_lolbas_binaries.yml b/lookups/csv/renamed_lolbas_binaries.yml new file mode 100644 index 00000000000..e76d3c31694 --- /dev/null +++ b/lookups/csv/renamed_lolbas_binaries.yml @@ -0,0 +1,14 @@ +name: renamed_lolbas_binaries +id: 8fcee872-392f-41ab-95fb-a50f8557b03e +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Splunk Threat Research Team +lookup_type: csv +description: A list of LOLBAS binaries and detailed information regarding their usage +default_match: 'false' +match_type: + - WILDCARD(original_file_name) +min_matches: 1 +max_matches: 1 +case_sensitive_match: false diff --git a/lookups/csv/renamed_popular_3rd_party_binaries.csv b/lookups/csv/renamed_popular_3rd_party_binaries.csv new file mode 100644 index 00000000000..b7a2150eb35 --- /dev/null +++ b/lookups/csv/renamed_popular_3rd_party_binaries.csv @@ -0,0 +1,43 @@ +original_file_name,software_name +7z.exe,7-Zip +7zg.exe,7-Zip +7zfm.exe,7-Zip +7za.exe,7-Zip +winrar*.exe,WinRAR +rar.exe,WinRAR +unrar.exe,WinRAR +peazip.exe,PeaZip +anydesk.exe,AnyDesk +teamviewer*.exe,TeamViewer +tv_w32.exe,TeamViewer +tv_x64.exe,TeamViewer +screenconnect*.exe,ConnectWise ScreenConnect +ateraagent.exe,Atera +srserver.exe,Splashtop +splashtopstreamer.exe,Splashtop +lmiguardiansvc.exe,LogMeIn +logmein.exe,LogMeIn +basupsrvc.exe,N-able Take Control +tcclient.exe,N-able Take Control +action1_agent.exe,Action1 +rutserv.exe,Remote Utilities +rfusclient.exe,Remote Utilities +advanced_ip_scanner*.exe,Advanced IP Scanner +advanced_port_scanner*.exe,Advanced Port Scanner +netscan.exe,SoftPerfect Network Scanner +ipscan.exe,Angry IP Scanner +adfind*.exe,AdFind +processhacker.exe,Process Hacker +systeminformer.exe,System Informer +winscp*.exe,WinSCP +rclone.exe,Rclone +plink.exe,PuTTY +putty*.exe,PuTTY +mobaxterm.exe,MobaXterm +ngrok.exe,Ngrok +cloudflared.exe,Cloudflared +chisel.exe,Chisel +webbrowserpassview.exe,NirSoft WebBrowserPassView +mailpv.exe,NirSoft Mail PassView +autoit3.exe,AutoIt +aut2exe.exe,AutoIt diff --git a/lookups/csv/renamed_popular_3rd_party_binaries.yml b/lookups/csv/renamed_popular_3rd_party_binaries.yml new file mode 100644 index 00000000000..0c684fe5e13 --- /dev/null +++ b/lookups/csv/renamed_popular_3rd_party_binaries.yml @@ -0,0 +1,14 @@ +name: renamed_popular_3rd_party_binaries +id: 83a56371-0a0f-4486-be21-8dc1d4d25e97 +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Splunk Threat Research Team +lookup_type: csv +description: A list of popular 3rd party Windows binaries and their software names +default_match: 'false' +match_type: + - WILDCARD(original_file_name) +min_matches: 1 +max_matches: 1 +case_sensitive_match: false diff --git a/lookups/csv/renamed_windows_command_interpreter_binaries.csv b/lookups/csv/renamed_windows_command_interpreter_binaries.csv new file mode 100644 index 00000000000..6aaea4fb288 --- /dev/null +++ b/lookups/csv/renamed_windows_command_interpreter_binaries.csv @@ -0,0 +1,13 @@ +original_file_name,description +bash.exe,"Bourne Again Shell interpreter; ships with WSL/Git for Windows/Cygwin and executes shell scripts and commands." +cmd.exe,"The native Windows command-line interpreter used to execute batch scripts and commands." +powershell.exe,"Windows PowerShell (v5.1 and earlier) command-line shell and scripting engine, heavily used for administration and living-off-the-land attacks." +powershell_ise.exe,"PowerShell Integrated Scripting Environment; GUI host for writing and running PowerShell scripts." +psexec*.c,"Sysinternals tool for executing processes on remote systems; frequently abused for lateral movement." +psexec*.exe,"Sysinternals tool for executing processes on remote systems; frequently abused for lateral movement." +psexec64.exe,"64-bit build of the Sysinternals PsExec remote execution tool." +pwsh.exe,"PowerShell (Core) 6+ cross-platform command-line shell and scripting engine, successor to powershell.exe." +sh.exe,"POSIX-compatible shell interpreter, typically bundled with Git for Windows/WSL/Cygwin, used to run shell scripts." +windowsterminal.exe,"Modern Windows Terminal application host that runs command-line shells (cmd, PowerShell, WSL) in tabs." +wsl.exe,"Windows Subsystem for Linux launcher; runs a Linux distribution/shell and executes Linux binaries or scripts on Windows." +wt.exe,"Windows Terminal executable, invoked via the wt command; launches and hosts terminal shell sessions." diff --git a/lookups/csv/renamed_windows_command_interpreter_binaries.yml b/lookups/csv/renamed_windows_command_interpreter_binaries.yml new file mode 100644 index 00000000000..0e364ef511c --- /dev/null +++ b/lookups/csv/renamed_windows_command_interpreter_binaries.yml @@ -0,0 +1,14 @@ +name: renamed_windows_command_interpreter_binaries +id: 2517d9fc-a1ee-4303-9a5b-15eaee7f418b +version: 1 +creation_date: '2026-09-23' +modification_date: '2026-09-23' +author: Splunk Threat Research Team +lookup_type: csv +description: A list of Windows command interpreter binaries and detailed information regarding their usage +default_match: 'false' +match_type: + - WILDCARD(original_file_name) +min_matches: 1 +max_matches: 1 +case_sensitive_match: false From f441771b1386cb1d919cff514baf68af16474940 Mon Sep 17 00:00:00 2001 From: onurmerdogan Date: Thu, 24 Sep 2026 00:03:30 +0200 Subject: [PATCH 02/10] update deprecated content --- .../deprecated/detect_html_help_renamed.yml | 2 +- .../deprecated/detect_mshta_renamed.yml | 2 +- .../deprecated/detect_renamed_7_zip.yml | 2 +- .../deprecated/detect_renamed_psexec.yml | 2 +- .../deprecated/detect_renamed_rclone.yml | 2 +- .../deprecated/detect_renamed_winrar.yml | 2 +- ...ous_microsoft_workflow_compiler_rename.yml | 2 +- .../deprecated/suspicious_msbuild_rename.yml | 2 +- ...indows_lolbas_executed_as_renamed_file.yml | 63 +++++++++++++++++++ .../windows_regsvr32_renamed_binary.yml | 2 +- .../windows_renamed_powershell_execution.yml | 2 +- ...ows_renamed_lolbas_binary_was_executed.yml | 6 +- 12 files changed, 76 insertions(+), 13 deletions(-) create mode 100644 detections/deprecated/windows_lolbas_executed_as_renamed_file.yml diff --git a/detections/deprecated/detect_html_help_renamed.yml b/detections/deprecated/detect_html_help_renamed.yml index 2dcbeaf831c..d97616dd19a 100644 --- a/detections/deprecated/detect_html_help_renamed.yml +++ b/detections/deprecated/detect_html_help_renamed.yml @@ -1,6 +1,6 @@ name: Detect HTML Help Renamed id: 62fed254-513b-460e-953d-79771493a9f3 -version: 14 +version: 15 creation_date: '2021-02-11' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/detect_mshta_renamed.yml b/detections/deprecated/detect_mshta_renamed.yml index 2587d9a661c..8efbe503324 100644 --- a/detections/deprecated/detect_mshta_renamed.yml +++ b/detections/deprecated/detect_mshta_renamed.yml @@ -1,6 +1,6 @@ name: Detect mshta renamed id: 8f45fcf0-5b68-11eb-ae93-0242ac130002 -version: 13 +version: 14 creation_date: '2021-01-15' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/detect_renamed_7_zip.yml b/detections/deprecated/detect_renamed_7_zip.yml index 1abebcc1f15..eda43f983cc 100644 --- a/detections/deprecated/detect_renamed_7_zip.yml +++ b/detections/deprecated/detect_renamed_7_zip.yml @@ -1,6 +1,6 @@ name: Detect Renamed 7-Zip id: 4057291a-b8cf-11eb-95fe-acde48001122 -version: 12 +version: 13 creation_date: '2021-06-03' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/detect_renamed_psexec.yml b/detections/deprecated/detect_renamed_psexec.yml index b201e36bffd..16b85591ae3 100644 --- a/detections/deprecated/detect_renamed_psexec.yml +++ b/detections/deprecated/detect_renamed_psexec.yml @@ -1,6 +1,6 @@ name: Detect Renamed PSExec id: 683e6196-b8e8-11eb-9a79-acde48001122 -version: 17 +version: 18 creation_date: '2021-06-03' modification_date: '2026-09-23' author: Michael Haag, Splunk, Alex Oberkircher, Github Community diff --git a/detections/deprecated/detect_renamed_rclone.yml b/detections/deprecated/detect_renamed_rclone.yml index cf1b820632c..7b81f3bb9c2 100644 --- a/detections/deprecated/detect_renamed_rclone.yml +++ b/detections/deprecated/detect_renamed_rclone.yml @@ -1,6 +1,6 @@ name: Detect Renamed RClone id: 6dca1124-b3ec-11eb-9328-acde48001122 -version: 12 +version: 13 creation_date: '2021-05-13' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/detect_renamed_winrar.yml b/detections/deprecated/detect_renamed_winrar.yml index 58651d38fcf..ab6ff9eccd6 100644 --- a/detections/deprecated/detect_renamed_winrar.yml +++ b/detections/deprecated/detect_renamed_winrar.yml @@ -1,6 +1,6 @@ name: Detect Renamed WinRAR id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122 -version: 16 +version: 17 creation_date: '2021-06-03' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml index 061234295d4..c149ac72fa0 100644 --- a/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,6 +1,6 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 -version: 14 +version: 15 creation_date: '2021-01-19' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/suspicious_msbuild_rename.yml b/detections/deprecated/suspicious_msbuild_rename.yml index 6d8edfa66d2..e38937e9d38 100644 --- a/detections/deprecated/suspicious_msbuild_rename.yml +++ b/detections/deprecated/suspicious_msbuild_rename.yml @@ -1,6 +1,6 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 -version: 14 +version: 15 creation_date: '2021-01-15' modification_date: '2026-09-23' author: Michael Haag, Splunk diff --git a/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml new file mode 100644 index 00000000000..877468c382a --- /dev/null +++ b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml @@ -0,0 +1,63 @@ +name: Windows LOLBAS Executed As Renamed File +id: fd496996-7d9e-4894-8d40-bb85b6192dc6 +version: 11 +creation_date: '2024-05-03' +modification_date: '2026-09-23' +author: Steven Dick +status: deprecated +type: TTP +description: The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. +data_source: + - Sysmon EventID 1 + - Windows Event Log Security 4688 + - CrowdStrike ProcessRollup2 +search: '| tstats `security_content_summariesonly` latest(Processes.parent_process) as parent_process, latest(Processes.process) as process, latest(Processes.process_guid) as process_guid count, min(_time) AS firstTime, max(_time) AS lastTime FROM datamodel=Endpoint.Processes where NOT Processes.original_file_name IN("-","unknown") AND NOT Processes.process_path IN ("*\\Program Files*","*\\PROGRA~*","*\\Windows\\System32\\*","*\\Windows\\Syswow64\\*") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product |`drop_dm_object_name(Processes)` | where NOT match(process_name, "(?i)".original_file_name) | lookup lolbas_file_path lolbas_file_name as original_file_name OUTPUT description as desc | search desc!="false" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_lolbas_executed_as_renamed_file_filter`' +how_to_implement: The detection is based on data that originates from Endpoint Detection and Response (EDR) agents. These agents are designed to provide security-related telemetry from the endpoints where the agent is installed. To implement this search, you must ingest logs that contain the process GUID, process name, and parent process. Additionally, you must ingest complete command-line executions. These logs must be processed using the appropriate Splunk Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. +known_false_positives: A certain amount of false positives are likely with this detection. MSI based installers often trigger for SETUPAPL.dll and vendors will often copy system exectables to a different path for application usage. +references: + - https://attack.mitre.org/techniques/T1036/ + - https://attack.mitre.org/techniques/T1036/003/ +drilldown_searches: + - name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ + - name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$", "$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: 7d + latest_offset: "0" +finding: + title: The file originally named $original_file_name$ was executed as $process_name$ on $dest$ + entity: + field: user + type: user + score: 50 +intermediate_findings: + entities: + - field: dest + type: system + score: 50 + message: The file originally named $original_file_name$ was executed as $process_name$ on $dest$ +threat_objects: + - field: process_name + type: process_name +analytic_story: + - Living Off The Land + - Masquerading - Rename System Utilities + - Windows Defense Evasion Tactics + - Water Gamayun +asset_type: Endpoint +mitre_attack_id: + - T1036.003 + - T1218.011 +product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +category: endpoint +security_domain: endpoint +deprecation_info: + reason: Detection deprecated due to renaming of its newer version. + removed_in_version: 6.8.0 + replacement_content: + - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/windows_regsvr32_renamed_binary.yml b/detections/deprecated/windows_regsvr32_renamed_binary.yml index f36818f47b9..db9a0c31ade 100644 --- a/detections/deprecated/windows_regsvr32_renamed_binary.yml +++ b/detections/deprecated/windows_regsvr32_renamed_binary.yml @@ -1,6 +1,6 @@ name: Windows Regsvr32 Renamed Binary id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a -version: 13 +version: 14 creation_date: '2022-10-27' modification_date: '2026-09-23' author: Teoderick Contreras, Splunk diff --git a/detections/deprecated/windows_renamed_powershell_execution.yml b/detections/deprecated/windows_renamed_powershell_execution.yml index 3ff0b4be4c2..1c19f163386 100644 --- a/detections/deprecated/windows_renamed_powershell_execution.yml +++ b/detections/deprecated/windows_renamed_powershell_execution.yml @@ -1,6 +1,6 @@ name: Windows Renamed Powershell Execution id: c08014de-cc5a-42de-9775-76ecd5b37bbd -version: 8 +version: 9 creation_date: '2022-10-27' modification_date: '2026-09-23' author: Teoderick Contreras, Nasreddine Bencherchali, Splunk diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml index 17dfc7c5ffa..b9b835466de 100644 --- a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -1,7 +1,7 @@ name: Windows Renamed LOLBAS Binary was Executed -id: fd496996-7d9e-4894-8d40-bb85b6192dc6 -version: 11 -creation_date: '2024-05-03' +id: 10c3850e-810d-41b4-a197-2f14d7883579 +version: 1 +creation_date: '2026-09-23' modification_date: '2026-09-23' author: Steven Dick, Onur Mustafa Erdogan, Splunk status: production From 9a43a2bba28049a1ce62b5061645b65fe02ebb0e Mon Sep 17 00:00:00 2001 From: onurmerdogan Date: Tue, 29 Sep 2026 14:20:56 +0200 Subject: [PATCH 03/10] incorporate feedback --- .../windows_renamed_command_interpreter_was_executed.yml | 8 ++++---- .../windows_renamed_lolbas_binary_was_executed.yml | 8 ++++---- ...s_renamed_popular_3rd_party_software_was_executed.yml | 9 +++++---- .../windows_renamed_python_binary_was_executed.yml | 6 +++--- lookups/csv/renamed_popular_3rd_party_binaries.csv | 2 +- .../csv/renamed_windows_command_interpreter_binaries.csv | 1 + 6 files changed, 18 insertions(+), 16 deletions(-) diff --git a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml index 469db2e44e9..64c901811de 100644 --- a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml +++ b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml @@ -12,7 +12,6 @@ description: |- be an indicator that an adversary is attempting to evade defenses or execute malicious code. data_source: - Sysmon EventID 1 - - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime @@ -37,7 +36,7 @@ search: |- | eval original_file_name=lower(original_file_name) | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | where NOT match(process_name, "(?i)".original_file_name) - | lookup renamed_windows_command_interpreter_binaries original_file_name OUTPUT description + | lookup local=t renamed_windows_command_interpreter_binaries original_file_name OUTPUT description | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_command_interpreter_was_executed_filter` @@ -54,6 +53,7 @@ references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ - https://attack.mitre.org/techniques/T1059/ + - https://redcanary.com/threat-detection-report/techniques/rename-system-utilities/ drilldown_searches: - name: View the detection results for - "$dest$" and "$user$" search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' @@ -67,8 +67,8 @@ intermediate_findings: entities: - field: dest type: system - score: 30 - message: Command Interpreter [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] + score: 20 + message: Command Interpreter [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - field: process_name type: process_name diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml index b9b835466de..3338a3d75f0 100644 --- a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -13,7 +13,6 @@ description: |- native binaries that can be abused by threat actors to perform tasks like executing malicious code. data_source: - Sysmon EventID 1 - - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime @@ -39,7 +38,7 @@ search: |- | eval original_file_name=lower(original_file_name) | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | where NOT match(process_name, "(?i)".original_file_name) - | lookup renamed_lolbas_binaries original_file_name OUTPUT description + | lookup local=t renamed_lolbas_binaries original_file_name OUTPUT description | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_lolbas_binary_was_executed_filter` @@ -55,6 +54,7 @@ known_false_positives: 3rd party software binaries sharing the same name as LOLB references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ + - https://redcanary.com/threat-detection-report/techniques/rename-system-utilities/ drilldown_searches: - name: View the detection results for - "$dest$" and "$user$" search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' @@ -68,8 +68,8 @@ intermediate_findings: entities: - field: dest type: system - score: 30 - message: LOLBAS utility [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] + score: 20 + message: LOLBAS utility [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - field: process_name type: process_name diff --git a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml index a16a53e5051..54e5fe80cf8 100644 --- a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml +++ b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml @@ -12,7 +12,6 @@ description: |- indicator that an adversary is attempting to evade defenses or execute malicious code. data_source: - Sysmon EventID 1 - - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime @@ -37,7 +36,7 @@ search: |- | eval original_file_name=lower(original_file_name) | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | where NOT match(process_name, "(?i)".original_file_name) - | lookup renamed_popular_3rd_party_binaries original_file_name OUTPUT software_name + | lookup local=t renamed_popular_3rd_party_binaries original_file_name OUTPUT description | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_popular_3rd_party_software_was_executed_filter` @@ -53,6 +52,8 @@ known_false_positives: 3rd party software binaries might have overlapping execut references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ + - https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ + - https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/ drilldown_searches: - name: View the detection results for - "$dest$" and "$user$" search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' @@ -66,8 +67,8 @@ intermediate_findings: entities: - field: dest type: system - score: 30 - message: Windows 3rd Party software [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] + score: 20 + message: Windows 3rd Party software [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - field: process_name type: process_name diff --git a/detections/endpoint/windows_renamed_python_binary_was_executed.yml b/detections/endpoint/windows_renamed_python_binary_was_executed.yml index baeb6163d38..71bde2bae79 100644 --- a/detections/endpoint/windows_renamed_python_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_python_binary_was_executed.yml @@ -12,7 +12,6 @@ description: |- an adversary is attempting to evade defenses or execute malicious code. data_source: - Sysmon EventID 1 - - Windows Event Log Security 4688 - CrowdStrike ProcessRollup2 search: |- | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime @@ -44,6 +43,7 @@ references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ - https://attack.mitre.org/techniques/T1059/006/ + - https://www.microsoft.com/en-us/security/blog/2026/02/05/clickfix-variant-crashfix-deploying-python-rat-trojan/ drilldown_searches: - name: View the detection results for - "$dest$" and "$user$" search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' @@ -57,8 +57,8 @@ intermediate_findings: entities: - field: dest type: system - score: 30 - message: Python binary [$original_file_name$] was renamed as [$process_name$] and later executed on [$dest$] + score: 20 + message: Python binary [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - field: process_name type: process_name diff --git a/lookups/csv/renamed_popular_3rd_party_binaries.csv b/lookups/csv/renamed_popular_3rd_party_binaries.csv index b7a2150eb35..d2a52926d0d 100644 --- a/lookups/csv/renamed_popular_3rd_party_binaries.csv +++ b/lookups/csv/renamed_popular_3rd_party_binaries.csv @@ -1,4 +1,4 @@ -original_file_name,software_name +original_file_name,description 7z.exe,7-Zip 7zg.exe,7-Zip 7zfm.exe,7-Zip diff --git a/lookups/csv/renamed_windows_command_interpreter_binaries.csv b/lookups/csv/renamed_windows_command_interpreter_binaries.csv index 6aaea4fb288..8809169991f 100644 --- a/lookups/csv/renamed_windows_command_interpreter_binaries.csv +++ b/lookups/csv/renamed_windows_command_interpreter_binaries.csv @@ -7,6 +7,7 @@ psexec*.c,"Sysinternals tool for executing processes on remote systems; frequent psexec*.exe,"Sysinternals tool for executing processes on remote systems; frequently abused for lateral movement." psexec64.exe,"64-bit build of the Sysinternals PsExec remote execution tool." pwsh.exe,"PowerShell (Core) 6+ cross-platform command-line shell and scripting engine, successor to powershell.exe." +pwsh.dll,"PowerShell (Core) 6+ cross-platform command-line shell and scripting engine, successor to powershell.exe." sh.exe,"POSIX-compatible shell interpreter, typically bundled with Git for Windows/WSL/Cygwin, used to run shell scripts." windowsterminal.exe,"Modern Windows Terminal application host that runs command-line shells (cmd, PowerShell, WSL) in tabs." wsl.exe,"Windows Subsystem for Linux launcher; runs a Linux distribution/shell and executes Linux binaries or scripts on Windows." From b0d691d0a18cdfc826cfc00f9ec6c3648ca3da4e Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Tue, 29 Sep 2026 10:17:03 -0700 Subject: [PATCH 04/10] strip erroneous CSV postfix from lookups --- .../windows_renamed_command_interpreter_was_executed.yml | 4 ++-- .../endpoint/windows_renamed_lolbas_binary_was_executed.yml | 4 ++-- ...indows_renamed_popular_3rd_party_software_was_executed.yml | 4 ++-- 3 files changed, 6 insertions(+), 6 deletions(-) diff --git a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml index 64c901811de..45fe64af53d 100644 --- a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml +++ b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml @@ -19,12 +19,12 @@ search: |- WHERE NOT Processes.original_file_name IN ("-","unknown") AND [ - | inputlookup renamed_windows_command_interpreter_binaries.csv + | inputlookup renamed_windows_command_interpreter_binaries | rename original_file_name as Processes.original_file_name | table Processes.original_file_name ] AND NOT [ - | inputlookup renamed_windows_command_interpreter_binaries.csv + | inputlookup renamed_windows_command_interpreter_binaries | rename original_file_name as Processes.process_name | table Processes.process_name ] diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml index 3338a3d75f0..fe64e48394f 100644 --- a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -20,12 +20,12 @@ search: |- WHERE NOT Processes.original_file_name IN ("-","unknown") AND [ - | inputlookup renamed_lolbas_binaries.csv + | inputlookup renamed_lolbas_binaries | rename original_file_name as Processes.original_file_name | table Processes.original_file_name ] AND NOT [ - | inputlookup renamed_lolbas_binaries.csv + | inputlookup renamed_lolbas_binaries | rename original_file_name as Processes.process_name | table Processes.process_name ] diff --git a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml index 54e5fe80cf8..ed3482e1ad3 100644 --- a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml +++ b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml @@ -19,12 +19,12 @@ search: |- WHERE NOT Processes.original_file_name IN ("-","unknown") AND [ - | inputlookup renamed_popular_3rd_party_binaries.csv + | inputlookup renamed_popular_3rd_party_binaries | rename original_file_name as Processes.original_file_name | table Processes.original_file_name ] AND NOT [ - | inputlookup renamed_popular_3rd_party_binaries.csv + | inputlookup renamed_popular_3rd_party_binaries | rename original_file_name as Processes.process_name | table Processes.process_name ] From a8f131777b6e1b0fbd4892bdd221e13c1e2d93de Mon Sep 17 00:00:00 2001 From: Onur Mustafa Erdogan <156806007+onurmerdogan@users.noreply.github.com> Date: Wed, 30 Sep 2026 17:01:33 +0200 Subject: [PATCH 05/10] Update windows_renamed_lolbas_binary_was_executed.yml --- .../endpoint/windows_renamed_lolbas_binary_was_executed.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml index fe64e48394f..0237ef1f812 100644 --- a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -90,7 +90,7 @@ security_domain: endpoint tests: - name: True Positive Test attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/cmd_lolbas_usage/cmd_lolbas_usage.log + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_lolbas_binary/renamed_lolbas_binary.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: XmlWinEventLog test_type: unit From 41c3a6320c83239a0adf71bdedb31f77c2af06c9 Mon Sep 17 00:00:00 2001 From: onurmerdogan Date: Thu, 1 Oct 2026 16:57:39 +0200 Subject: [PATCH 06/10] adding back unit test info --- detections/deprecated/detect_html_help_renamed.yml | 7 +++++++ detections/deprecated/detect_mshta_renamed.yml | 7 +++++++ detections/deprecated/detect_renamed_7_zip.yml | 7 +++++++ detections/deprecated/detect_renamed_psexec.yml | 7 +++++++ detections/deprecated/detect_renamed_rclone.yml | 7 +++++++ detections/deprecated/detect_renamed_winrar.yml | 7 +++++++ .../suspicious_microsoft_workflow_compiler_rename.yml | 7 +++++++ detections/deprecated/suspicious_msbuild_rename.yml | 7 +++++++ .../deprecated/windows_lolbas_executed_as_renamed_file.yml | 7 +++++++ detections/deprecated/windows_regsvr32_renamed_binary.yml | 7 +++++++ .../deprecated/windows_renamed_powershell_execution.yml | 7 +++++++ 11 files changed, 77 insertions(+) diff --git a/detections/deprecated/detect_html_help_renamed.yml b/detections/deprecated/detect_html_help_renamed.yml index d97616dd19a..70df2b50613 100644 --- a/detections/deprecated/detect_html_help_renamed.yml +++ b/detections/deprecated/detect_html_help_renamed.yml @@ -46,6 +46,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/detect_mshta_renamed.yml b/detections/deprecated/detect_mshta_renamed.yml index 8efbe503324..0456a4d4b91 100644 --- a/detections/deprecated/detect_mshta_renamed.yml +++ b/detections/deprecated/detect_mshta_renamed.yml @@ -45,6 +45,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/detect_renamed_7_zip.yml b/detections/deprecated/detect_renamed_7_zip.yml index eda43f983cc..c838fae589c 100644 --- a/detections/deprecated/detect_renamed_7_zip.yml +++ b/detections/deprecated/detect_renamed_7_zip.yml @@ -45,6 +45,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/detect_renamed_psexec.yml b/detections/deprecated/detect_renamed_psexec.yml index 16b85591ae3..7295b0be66b 100644 --- a/detections/deprecated/detect_renamed_psexec.yml +++ b/detections/deprecated/detect_renamed_psexec.yml @@ -60,6 +60,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/detect_renamed_rclone.yml b/detections/deprecated/detect_renamed_rclone.yml index 7b81f3bb9c2..e77b2fe6e0f 100644 --- a/detections/deprecated/detect_renamed_rclone.yml +++ b/detections/deprecated/detect_renamed_rclone.yml @@ -49,6 +49,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/detect_renamed_winrar.yml b/detections/deprecated/detect_renamed_winrar.yml index ab6ff9eccd6..f2fe9cd08a7 100644 --- a/detections/deprecated/detect_renamed_winrar.yml +++ b/detections/deprecated/detect_renamed_winrar.yml @@ -45,6 +45,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml index c149ac72fa0..e9657e6d3e6 100644 --- a/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml @@ -49,6 +49,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/suspicious_msbuild_rename.yml b/detections/deprecated/suspicious_msbuild_rename.yml index e38937e9d38..e38928fe309 100644 --- a/detections/deprecated/suspicious_msbuild_rename.yml +++ b/detections/deprecated/suspicious_msbuild_rename.yml @@ -51,6 +51,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml index 877468c382a..c31a285a7e1 100644 --- a/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml +++ b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml @@ -56,6 +56,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/cmd_lolbas_usage/cmd_lolbas_usage.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to renaming of its newer version. removed_in_version: 6.8.0 diff --git a/detections/deprecated/windows_regsvr32_renamed_binary.yml b/detections/deprecated/windows_regsvr32_renamed_binary.yml index db9a0c31ade..f9a1c6cfa0b 100644 --- a/detections/deprecated/windows_regsvr32_renamed_binary.yml +++ b/detections/deprecated/windows_regsvr32_renamed_binary.yml @@ -58,6 +58,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_3/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 diff --git a/detections/deprecated/windows_renamed_powershell_execution.yml b/detections/deprecated/windows_renamed_powershell_execution.yml index 1c19f163386..15784a4b2ea 100644 --- a/detections/deprecated/windows_renamed_powershell_execution.yml +++ b/detections/deprecated/windows_renamed_powershell_execution.yml @@ -42,6 +42,13 @@ product: - Splunk Cloud category: endpoint security_domain: endpoint +tests: + - name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_powershell/renamed_powershell.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: XmlWinEventLog + test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. removed_in_version: 6.8.0 From 981d94c911462ca2c4906697d7f4db90a52aafba Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Fri, 2 Oct 2026 12:17:06 +0200 Subject: [PATCH 07/10] update removed_in_version info --- detections/deprecated/detect_html_help_renamed.yml | 2 +- detections/deprecated/detect_mshta_renamed.yml | 2 +- detections/deprecated/detect_renamed_7_zip.yml | 2 +- detections/deprecated/detect_renamed_psexec.yml | 2 +- detections/deprecated/detect_renamed_rclone.yml | 2 +- detections/deprecated/detect_renamed_winrar.yml | 2 +- .../suspicious_microsoft_workflow_compiler_rename.yml | 2 +- detections/deprecated/suspicious_msbuild_rename.yml | 2 +- .../deprecated/windows_lolbas_executed_as_renamed_file.yml | 2 +- detections/deprecated/windows_regsvr32_renamed_binary.yml | 2 +- detections/deprecated/windows_renamed_powershell_execution.yml | 2 +- 11 files changed, 11 insertions(+), 11 deletions(-) diff --git a/detections/deprecated/detect_html_help_renamed.yml b/detections/deprecated/detect_html_help_renamed.yml index 70df2b50613..6a71fb80287 100644 --- a/detections/deprecated/detect_html_help_renamed.yml +++ b/detections/deprecated/detect_html_help_renamed.yml @@ -55,6 +55,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/detect_mshta_renamed.yml b/detections/deprecated/detect_mshta_renamed.yml index 0456a4d4b91..a18668a17fe 100644 --- a/detections/deprecated/detect_mshta_renamed.yml +++ b/detections/deprecated/detect_mshta_renamed.yml @@ -54,6 +54,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/detect_renamed_7_zip.yml b/detections/deprecated/detect_renamed_7_zip.yml index c838fae589c..fea1e5e5ce5 100644 --- a/detections/deprecated/detect_renamed_7_zip.yml +++ b/detections/deprecated/detect_renamed_7_zip.yml @@ -54,6 +54,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/deprecated/detect_renamed_psexec.yml b/detections/deprecated/detect_renamed_psexec.yml index 7295b0be66b..52e1bdf8899 100644 --- a/detections/deprecated/detect_renamed_psexec.yml +++ b/detections/deprecated/detect_renamed_psexec.yml @@ -69,6 +69,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed Command Interpreter was Executed diff --git a/detections/deprecated/detect_renamed_rclone.yml b/detections/deprecated/detect_renamed_rclone.yml index e77b2fe6e0f..7e9bccd3330 100644 --- a/detections/deprecated/detect_renamed_rclone.yml +++ b/detections/deprecated/detect_renamed_rclone.yml @@ -58,6 +58,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/deprecated/detect_renamed_winrar.yml b/detections/deprecated/detect_renamed_winrar.yml index f2fe9cd08a7..215d1d0a53e 100644 --- a/detections/deprecated/detect_renamed_winrar.yml +++ b/detections/deprecated/detect_renamed_winrar.yml @@ -54,6 +54,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed Popular 3rd Party Software was Executed diff --git a/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml index e9657e6d3e6..ec137b5b28c 100644 --- a/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/deprecated/suspicious_microsoft_workflow_compiler_rename.yml @@ -58,6 +58,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/suspicious_msbuild_rename.yml b/detections/deprecated/suspicious_msbuild_rename.yml index e38928fe309..4fb2bbb641e 100644 --- a/detections/deprecated/suspicious_msbuild_rename.yml +++ b/detections/deprecated/suspicious_msbuild_rename.yml @@ -60,6 +60,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml index c31a285a7e1..aa90a9b6bce 100644 --- a/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml +++ b/detections/deprecated/windows_lolbas_executed_as_renamed_file.yml @@ -65,6 +65,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to renaming of its newer version. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/windows_regsvr32_renamed_binary.yml b/detections/deprecated/windows_regsvr32_renamed_binary.yml index f9a1c6cfa0b..4d6940c412e 100644 --- a/detections/deprecated/windows_regsvr32_renamed_binary.yml +++ b/detections/deprecated/windows_regsvr32_renamed_binary.yml @@ -67,6 +67,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed LOLBAS Binary was Executed diff --git a/detections/deprecated/windows_renamed_powershell_execution.yml b/detections/deprecated/windows_renamed_powershell_execution.yml index 15784a4b2ea..dbb8ef8e183 100644 --- a/detections/deprecated/windows_renamed_powershell_execution.yml +++ b/detections/deprecated/windows_renamed_powershell_execution.yml @@ -51,6 +51,6 @@ tests: test_type: unit deprecation_info: reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. - removed_in_version: 6.8.0 + removed_in_version: 6.10.0 replacement_content: - Windows Renamed Command Interpreter was Executed From 5c2e4c5fd67c7e55512b1f1446abd8384caabad8 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Fri, 2 Oct 2026 12:59:51 +0200 Subject: [PATCH 08/10] small format updates --- ...named_command_interpreter_was_executed.yml | 48 +++++++++------ ...ows_renamed_lolbas_binary_was_executed.yml | 58 ++++++++++++------- ...opular_3rd_party_software_was_executed.yml | 48 +++++++++------ 3 files changed, 98 insertions(+), 56 deletions(-) diff --git a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml index 45fe64af53d..3e97a3ea439 100644 --- a/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml +++ b/detections/endpoint/windows_renamed_command_interpreter_was_executed.yml @@ -7,36 +7,47 @@ author: Onur Mustafa Erdogan, Splunk status: production type: Anomaly description: |- - The following analytic identifies a Windows command interpreter process being executed where it's process - name does not match it's original file name attribute. Processes that have been renamed and executed may - be an indicator that an adversary is attempting to evade defenses or execute malicious code. + The following analytic identifies a Windows command interpreter process being executed where it's process name does not match it's original file name attribute. + Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. data_source: - Sysmon EventID 1 - CrowdStrike ProcessRollup2 search: |- - | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime - FROM datamodel=Endpoint.Processes - WHERE - NOT Processes.original_file_name IN ("-","unknown") - AND [ + | tstats `security_content_summariesonly` + count min(_time) AS firstTime + max(_time) AS lastTime + + FROM datamodel=Endpoint.Processes WHERE + + NOT Processes.original_file_name IN ("-","unknown") + [ | inputlookup renamed_windows_command_interpreter_binaries | rename original_file_name as Processes.original_file_name | table Processes.original_file_name - ] - AND NOT [ + ] + NOT [ | inputlookup renamed_windows_command_interpreter_binaries | rename original_file_name as Processes.process_name | table Processes.process_name - ] - by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec - Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path - Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id - Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + ] + + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid + Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path + Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | where NOT match(process_name, "(?i)".original_file_name) + | lookup local=t renamed_windows_command_interpreter_binaries original_file_name OUTPUT description + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_command_interpreter_was_executed_filter` @@ -48,7 +59,8 @@ how_to_implement: |- Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: 3rd party software binaries sharing the same name as Windows command interpreter binaries may trigger false positives. +known_false_positives: |- + 3rd party software binaries sharing the same name as Windows command interpreter binaries may trigger false positives. references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ @@ -70,8 +82,8 @@ intermediate_findings: score: 20 message: Command Interpreter [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - - field: process_name - type: process_name + - field: process_path + type: file_path analytic_story: - Living Off The Land - Masquerading - Rename System Utilities diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml index 0237ef1f812..bd4176d22ec 100644 --- a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -7,38 +7,55 @@ author: Steven Dick, Onur Mustafa Erdogan, Splunk status: production type: Anomaly description: |- - The following analytic identifies a LOLBAS process being executed where it's process name does not match - it's original file name attribute. Processes that have been renamed and executed may be an indicator that - an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows - native binaries that can be abused by threat actors to perform tasks like executing malicious code. + The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. + Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. + The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. data_source: - Sysmon EventID 1 - CrowdStrike ProcessRollup2 search: |- - | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime - FROM datamodel=Endpoint.Processes - WHERE - NOT Processes.original_file_name IN ("-","unknown") - AND [ + | tstats `security_content_summariesonly` + count min(_time) AS firstTime + max(_time) AS lastTime + + FROM datamodel=Endpoint.Processes WHERE + + NOT Processes.original_file_name IN ("-","unknown") + [ | inputlookup renamed_lolbas_binaries | rename original_file_name as Processes.original_file_name | table Processes.original_file_name - ] - AND NOT [ + ] + NOT [ | inputlookup renamed_lolbas_binaries | rename original_file_name as Processes.process_name | table Processes.process_name - ] - AND NOT process_name IN ('excelcnv.exe', 'installutil64.exe', 'protoc~1.exe', 'regwrite.exe', 'vzshadow.exe') - by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec - Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path - Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id - Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + ] + NOT process_name IN ( + 'excelcnv.exe', + 'installutil64.exe', + 'protoc~1.exe', + 'regwrite.exe', + 'vzshadow.exe' + ) + + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid + Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path + Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | where NOT match(process_name, "(?i)".original_file_name) + | lookup local=t renamed_lolbas_binaries original_file_name OUTPUT description + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_lolbas_binary_was_executed_filter` @@ -50,7 +67,8 @@ how_to_implement: |- Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: 3rd party software binaries sharing the same name as LOLBAS utilities may trigger false positives. +known_false_positives: |- + 3rd party software binaries sharing the same name as LOLBAS utilities may trigger false positives. references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ @@ -71,8 +89,8 @@ intermediate_findings: score: 20 message: LOLBAS utility [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - - field: process_name - type: process_name + - field: process_path + type: file_path analytic_story: - Living Off The Land - Masquerading - Rename System Utilities diff --git a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml index ed3482e1ad3..374458d818c 100644 --- a/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml +++ b/detections/endpoint/windows_renamed_popular_3rd_party_software_was_executed.yml @@ -7,36 +7,47 @@ author: Onur Mustafa Erdogan, Splunk status: production type: Anomaly description: |- - The following analytic identifies a popular 3rd party software process being executed where it's process name - does not match it's original file name attribute. Processes that have been renamed and executed may be an - indicator that an adversary is attempting to evade defenses or execute malicious code. + The following analytic identifies a popular 3rd party software process being executed where it's process name does not match it's original file name attribute. + Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. data_source: - Sysmon EventID 1 - CrowdStrike ProcessRollup2 search: |- - | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime - FROM datamodel=Endpoint.Processes - WHERE - NOT Processes.original_file_name IN ("-","unknown") - AND [ + | tstats `security_content_summariesonly` + count min(_time) AS firstTime + max(_time) AS lastTime + + FROM datamodel=Endpoint.Processes WHERE + + NOT Processes.original_file_name IN ("-","unknown") + [ | inputlookup renamed_popular_3rd_party_binaries | rename original_file_name as Processes.original_file_name | table Processes.original_file_name - ] - AND NOT [ + ] + NOT [ | inputlookup renamed_popular_3rd_party_binaries | rename original_file_name as Processes.process_name | table Processes.process_name - ] - by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec - Processes.parent_process_guid Processes.parent_process_id Processes.parent_process_name Processes.parent_process_path - Processes.process Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id - Processes.process_integrity_level Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product + ] + + by Processes.action Processes.dest Processes.original_file_name Processes.parent_process + Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id + Processes.parent_process_name Processes.parent_process_path + Processes.process Processes.process_exec Processes.process_guid + Processes.process_hash Processes.process_id Processes.process_integrity_level + Processes.process_name Processes.process_path + Processes.user Processes.user_id Processes.vendor_product + | `drop_dm_object_name(Processes)` + | eval original_file_name=lower(original_file_name) + | where NOT match(process_name, "(?i)^".replace(original_file_name,"(?i).exe","")) | where NOT match(process_name, "(?i)".original_file_name) + | lookup local=t renamed_popular_3rd_party_binaries original_file_name OUTPUT description + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_popular_3rd_party_software_was_executed_filter` @@ -48,7 +59,8 @@ how_to_implement: |- Technology Add-ons that are specific to the EDR product. The logs must also be mapped to the `Processes` node of the `Endpoint` data model. Use the Splunk Common Information Model (CIM) to normalize the field names and speed up the data modeling process. -known_false_positives: 3rd party software binaries might have overlapping executable names. +known_false_positives: |- + 3rd party software binaries might have overlapping executable names. references: - https://attack.mitre.org/techniques/T1036/ - https://attack.mitre.org/techniques/T1036/003/ @@ -70,8 +82,8 @@ intermediate_findings: score: 20 message: Windows 3rd Party software [$original_file_name$] was renamed as [$process_path$] and later executed on [$dest$] threat_objects: - - field: process_name - type: process_name + - field: process_path + type: file_path analytic_story: - Living Off The Land - Masquerading - Rename System Utilities From aa0845d0d6d62014e9fcf3fe01570403491004fd Mon Sep 17 00:00:00 2001 From: onurmerdogan Date: Mon, 5 Oct 2026 12:28:03 +0200 Subject: [PATCH 09/10] fix SPL --- .../windows_renamed_python_binary_was_executed.yml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/detections/endpoint/windows_renamed_python_binary_was_executed.yml b/detections/endpoint/windows_renamed_python_binary_was_executed.yml index 71bde2bae79..4f0731c4512 100644 --- a/detections/endpoint/windows_renamed_python_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_python_binary_was_executed.yml @@ -17,6 +17,11 @@ search: |- | tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime FROM datamodel=Endpoint.Processes WHERE + Processes.original_file_name IN ( + "py*", + "python*", + "ipyw*" + ) NOT Processes.original_file_name IN ("-","unknown") NOT Processes.process_name IN ("dwagent.exe", "WinUtils.exe") by Processes.action Processes.dest Processes.original_file_name Processes.parent_process Processes.parent_process_exec @@ -26,7 +31,7 @@ search: |- | `drop_dm_object_name(Processes)` | eval original_file_name=lower(original_file_name) | regex original_file_name="(?i)^(?:py|pyw|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+)\.exe$" - | regex process_name="(?i)^(?:py|pyw|pip|pip3|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+|pip3\.\w+|idle3\.\w+)\.exe$" + | regex process_name!="(?i)^(?:py|pyw|pip|pip3|python|pythonw|python32|python64|pythonw32|pythonw64|ipyw32|ipyw64|python3|pythonw3|python3\.\w+|pythonw3\.\w+|pip3\.\w+|idle3\.\w+)\.exe$" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_renamed_python_binary_was_executed_filter` From d09cba406f3e4627f73d83aabe8dc7351a5606c2 Mon Sep 17 00:00:00 2001 From: Onur Mustafa Erdogan <156806007+onurmerdogan@users.noreply.github.com> Date: Mon, 5 Oct 2026 13:09:35 +0200 Subject: [PATCH 10/10] Update windows_renamed_lolbas_binary_was_executed.yml --- .../windows_renamed_lolbas_binary_was_executed.yml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml index bd4176d22ec..f0842c81eb4 100644 --- a/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml +++ b/detections/endpoint/windows_renamed_lolbas_binary_was_executed.yml @@ -32,11 +32,11 @@ search: |- | table Processes.process_name ] NOT process_name IN ( - 'excelcnv.exe', - 'installutil64.exe', - 'protoc~1.exe', - 'regwrite.exe', - 'vzshadow.exe' + "excelcnv.exe", + "installutil64.exe", + "protoc~1.exe", + "regwrite.exe", + "vzshadow.exe" ) by Processes.action Processes.dest Processes.original_file_name Processes.parent_process