Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions detections/endpoint/detect_new_local_admin_account.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Detect New Local Admin account
id: b25f6f62-0712-43c1-b203-083231ffd97d
version: 13
version: 14
creation_date: '2020-04-29'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: David Dorsey, Splunk
status: production
type: TTP
Expand All @@ -21,7 +21,7 @@ search: |
(
Group_Name=Administrators
OR
TargetUserName=Administrators
Target_User_Name=Administrators
)
)
)
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Kerberos Pre-Authentication Flag Disabled in UserAccountControl
id: 0cb847ee-9423-11ec-b2df-acde48001122
version: 12
version: 13
creation_date: '2022-02-23'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Mauricio Velazco, Splunk
status: production
type: TTP
Expand All @@ -11,7 +11,7 @@ data_source:
- Windows Event Log Security 4738
search: >
`wineventlog_security` EventCode=4738 UserAccountControl="*%%2096*"
| rename TargetUserName as user, SubjectUserName as actor | stats count earliest(_time) as firstTime latest(_time) as lastTime by actor, user, dest
| rename Target_User_Name as user, SubjectUserName as actor | stats count earliest(_time) as firstTime latest(_time) as lastTime by actor, user, dest
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `kerberos_pre_authentication_flag_disabled_in_useraccountcontrol_filter`
Expand Down
8 changes: 4 additions & 4 deletions detections/endpoint/kerberos_user_enumeration.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,18 @@
name: Kerberos User Enumeration
id: d82d4af4-a0bd-11ec-9445-3e22fbd008af
version: 13
version: 14
creation_date: '2022-03-11'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Mauricio Velazco, Splunk
status: production
type: Anomaly
description: The following analytic detects an unusual number of Kerberos Ticket Granting Ticket (TGT) requests for non-existing users from a single source endpoint. It leverages Event ID 4768 and identifies anomalies using the 3-sigma statistical rule. This behavior is significant as it may indicate an adversary performing a user enumeration attack against Active Directory. If confirmed malicious, the attacker could validate a list of usernames, potentially leading to further attacks such as brute force or credential stuffing, compromising the security of the environment.
data_source:
- Windows Event Log Security 4768
search: |-
`wineventlog_security` EventCode=4768 Status=0x6 TargetUserName!="*$"
`wineventlog_security` EventCode=4768 Status=0x6 Target_User_Name!="*$"
| bucket span=2m _time
| stats dc(TargetUserName) AS unique_accounts values(TargetUserName) as tried_accounts values(dest) as dest
| stats dc(Target_User_Name) AS unique_accounts values(Target_User_Name) as tried_accounts values(dest) as dest
BY _time, src_ip
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std
BY src_ip
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: PetitPotam Suspicious Kerberos TGT Request
id: e3ef244e-0a67-11ec-abf2-acde48001122
version: 11
version: 12
creation_date: '2021-09-01'
modification_date: '2026-07-04'
modification_date: '2026-09-24'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: TTP
Expand All @@ -13,12 +13,12 @@ search: |-
`wineventlog_security`
EventCode=4768
src!="::1"
TargetUserName=*$
Target_User_Name=*$
CertThumbprint!=""
PreAuthType=2
| stats count min(_time) as firstTime
max(_time) as lastTime
BY dest TargetUserName PreAuthType CertThumbprint src action
BY dest Target_User_Name PreAuthType CertThumbprint src action
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `petitpotam_suspicious_kerberos_tgt_request_filter`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Suspicious Kerberos Service Ticket Request
id: 8b1297bc-6204-11ec-b7c4-acde48001122
version: 12
version: 13
creation_date: '2021-12-20'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Mauricio Velazco, Splunk
status: production
type: TTP
Expand All @@ -11,10 +11,10 @@ data_source:
- Windows Event Log Security 4769
search: |-
`wineventlog_security` EventCode=4769
| eval isSuspicious = if(lower(ServiceName) = lower(mvindex(split(TargetUserName,"@"),0)),1,0)
| eval isSuspicious = if(lower(ServiceName) = lower(mvindex(split(Target_User_Name,"@"),0)),1,0)
| where isSuspicious = 1
| rename Computer as dest
| rename TargetUserName as user
| rename Target_User_Name as user
| table _time, dest, src_ip, user, ServiceName, Error_Code, isSuspicious
| `suspicious_kerberos_service_ticket_request_filter`
how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Suspicious Ticket Granting Ticket Request
id: d77d349e-6269-11ec-9cfe-acde48001122
version: 10
version: 11
creation_date: '2021-12-21'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
Expand All @@ -11,12 +11,12 @@ data_source:
- Windows Event Log Security 4768
- Windows Event Log Security 4781
search: |-
`wineventlog_security` (EventCode=4781 OldTargetUserName="*$" NewTargetUserName!="*$") OR (EventCode=4768 TargetUserName!="*$")
| eval RenamedComputerAccount = coalesce(NewTargetUserName, TargetUserName)
`wineventlog_security` (EventCode=4781 OldTargetUserName="*$" NewTargetUserName!="*$") OR (EventCode=4768 Target_User_Name!="*$")
| eval RenamedComputerAccount = coalesce(NewTargetUserName, Target_User_Name)
| transaction RenamedComputerAccount startswith=(EventCode=4781) endswith=(EventCode=4768)
| eval short_lived=case((duration<2),"TRUE")
| search short_lived = TRUE
| table _time, Computer, EventCode, TargetUserName, RenamedComputerAccount, short_lived
| table _time, Computer, EventCode, Target_User_Name, RenamedComputerAccount, short_lived
| rename Computer as dest
| `suspicious_ticket_granting_ticket_request_filter`
how_to_implement: To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: Windows Access Token Manipulation SeDebugPrivilege
id: 6ece9ed0-5f92-4315-889d-48560472b188
version: 24
version: 25
creation_date: '2022-09-05'
modification_date: '2026-08-14'
modification_date: '2026-09-24'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
description: The following analytic detects a process enabling the "SeDebugPrivilege" privilege token. It leverages Windows Security Event Logs with EventCode 4703, filtering out common legitimate processes. This activity is significant because SeDebugPrivilege allows a process to inspect and modify the memory of other processes, potentially leading to credential dumping or code injection. If confirmed malicious, an attacker could gain extensive control over system processes, enabling them to escalate privileges, persist in the environment, or access sensitive information.
data_source:
- Windows Event Log Security 4703
search: '`wineventlog_security` EventCode=4703 EnabledPrivilegeList = "*SeDebugPrivilege*" AND NOT(ProcessName IN ("*\\Program File*", "*\\System32\\lsass.exe*", "*\\SysWOW64\\lsass.exe*", "*\\SysWOW64\\svchost.exe*", "*\\System32\\svchost.exe*")) | stats count min(_time) as firstTime max(_time) as lastTime by Computer ProcessName ProcessId SubjectDomainName SubjectUserName SubjectUserSid TargetUserName TargetLogonId TargetDomainName EnabledPrivilegeList action dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_access_token_manipulation_sedebugprivilege_filter`'
search: '`wineventlog_security` EventCode=4703 EnabledPrivilegeList = "*SeDebugPrivilege*" AND NOT(ProcessName IN ("*\\Program File*", "*\\System32\\lsass.exe*", "*\\SysWOW64\\lsass.exe*", "*\\SysWOW64\\svchost.exe*", "*\\System32\\svchost.exe*")) | stats count min(_time) as firstTime max(_time) as lastTime by Computer ProcessName ProcessId SubjectDomainName SubjectUserName SubjectUserSid Target_User_Name TargetLogonId TargetDomainName EnabledPrivilegeList action dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_access_token_manipulation_sedebugprivilege_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4703 EventCode enabled. The Windows TA is also required.
known_false_positives: Some native binaries and browser applications may request SeDebugPrivilege. Filter as needed.
references:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Windows AD Suspicious Attribute Modification
id: 5682052e-ce55-4f9f-8d28-59191420b7e0
version: 10
version: 11
creation_date: '2024-07-01'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Dean Luxton
status: production
type: TTP
Expand All @@ -15,7 +15,7 @@ search: |-
| rename SubjectLogonId as TargetLogonId, src_user as initiator, _time as eventTime
| appendpipe [
| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"]
| stats min(eventTime) as _time values(initiator) as src_user, values(DSName) as targetDomain, values(ObjectDN) as ObjectDN, values(ObjectClass) as ObjectClass, values(src_category) as src_category, values(src_ip) as src_ip values(LogonType) as LogonType values(AttributeValue) as AttributeValue values(AttributeLDAPDisplayName) as AttributeLDAPDisplayName
| stats min(eventTime) as _time values(initiator) as src_user, values(DSName) as targetDomain, values(ObjectDN) as ObjectDN, values(ObjectClass) as ObjectClass, values(src_category) as src_category, values(src_ip) as src_ip values(Logon_Type) as Logon_Type values(AttributeValue) as AttributeValue values(AttributeLDAPDisplayName) as AttributeLDAPDisplayName
BY TargetLogonId
| rex field=ObjectDN "^CN=(?P<cn>.*?),[A-Z]{2}\="
| eval dest=if(ObjectClass="computer",cn,null), user=if(ObjectClass="user",cn,null)
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Windows Computer Account Changed to Domain Controller
id: f9df6250-fa45-4f62-bc9a-768c60bf99b2
version: 2
version: 3
creation_date: '2026-05-05'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Raven Tait, Splunk
status: production
type: TTP
Expand All @@ -19,7 +19,7 @@ search: |-
| fillnull
| stats count min(_time) as firstTime
max(_time) as lastTime
by Computer TargetUserName UserAccountControl EventID
by Computer Target_User_Name UserAccountControl EventID

| rename Computer as dest
| `security_content_ctime(firstTime)`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,19 +1,19 @@
name: Windows Computer Account Requesting Kerberos Ticket
id: fb3b2bb3-75a4-4279-848a-165b42624770
version: 10
version: 11
creation_date: '2022-04-28'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Michael Haag, Splunk
status: production
type: TTP
description: The following analytic detects a computer account requesting a Kerberos ticket, which is unusual as typically user accounts request these tickets. This detection leverages Windows Security Event Logs, specifically EventCode 4768, to identify instances where the TargetUserName ends with a dollar sign ($), indicating a computer account. This activity is significant because it may indicate the use of tools like KrbUpRelay or other Kerberos-based attacks. If confirmed malicious, this could allow attackers to impersonate computer accounts, potentially leading to unauthorized access and lateral movement within the network.
data_source:
- Windows Event Log Security 4768
search: |-
`wineventlog_security` EventCode=4768 TargetUserName="*$" src_ip!="::1"
`wineventlog_security` EventCode=4768 Target_User_Name="*$" src_ip!="::1"
| stats count min(_time) as firstTime max(_time) as lastTime
BY dest, subject, action,
user, TargetUserName, src_ip
user, Target_User_Name, src_ip
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_computer_account_requesting_kerberos_ticket_filter`
Expand Down
8 changes: 4 additions & 4 deletions detections/endpoint/windows_dnsadmins_new_member_added.yml
Original file line number Diff line number Diff line change
@@ -1,17 +1,17 @@
name: Windows DnsAdmins New Member Added
id: 27e600aa-77f8-4614-bc80-2662a67e2f48
version: 12
version: 13
creation_date: '2023-03-28'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Mauricio Velazco, Splunk
status: production
type: TTP
description: The following analytic detects the addition of a new member to the DnsAdmins group in Active Directory by leveraging Event ID 4732. This detection uses security event logs to identify changes to this high-privilege group. Monitoring this activity is crucial because members of the DnsAdmins group can manage the DNS service, often running on Domain Controllers, and potentially execute malicious code with SYSTEM privileges. If confirmed malicious, this activity could allow an attacker to escalate privileges and gain control over critical domain services, posing a significant security risk.
data_source:
- Windows Event Log Security 4732
search: |-
`wineventlog_security` EventCode=4732 TargetUserName=DnsAdmins
| stats min(_time) as firstTime max(_time) as lastTime values(TargetUserName) as target_users_added values(user) as user
`wineventlog_security` EventCode=4732 Target_User_Name=DnsAdmins
| stats min(_time) as firstTime max(_time) as lastTime values(Target_User_Name) as target_users_added values(user) as user
BY dest src_user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
Expand Down
Original file line number Diff line number Diff line change
@@ -1,22 +1,22 @@
name: Windows Domain Admin Impersonation Indicator
id: 10381f93-6d38-470a-9c30-d25478e3bd3f
version: 12
version: 13
creation_date: '2023-10-06'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Mauricio Velazco, Splunk
status: production
type: TTP
description: The following analytic identifies potential Kerberos ticket forging attacks, specifically the Diamond Ticket attack. This is detected when a user logs into a host and the GroupMembership field in event 4627 indicates a privileged group (e.g., Domain Admins), but the user does not actually belong to that group in the directory service. The detection leverages Windows Security Event Log 4627, which logs account logon events. The analytic cross-references the GroupMembership field from the event against a pre-populated lookup of actual group memberships. Its crucial to note that the accuracy and effectiveness of this detection heavily rely on the users diligence in populating and regularly updating this lookup table. Any discrepancies between the events GroupMembership and the lookup indicate potential ticket forging. Kerberos ticket forging, especially the Diamond Ticket attack, allows attackers to impersonate any user and potentially gain unauthorized access to resources. By forging a ticket that indicates membership in a privileged group, an attacker can bypass security controls and gain elevated privileges. Detecting such discrepancies in group memberships during logon events can be a strong indicator of this attack in progress, making it crucial for security teams to monitor and investigate. If validated as a true positive, this indicates that an attacker has successfully forged a Kerberos ticket and may have gained unauthorized access to critical resources, potentially with elevated privileges.
data_source:
- Windows Event Log Security 4627
search: |-
`wineventlog_security` EventCode=4627 LogonType=3 NOT TargetUserName IN ("*$", "SYSTEM", "DWM-*","LOCAL SERVICE","NETWORK SERVICE", "ANONYMOUS LOGON", "UMFD-*")
`wineventlog_security` EventCode=4627 Logon_Type=3 NOT Target_User_Name IN ("*$", "SYSTEM", "DWM-*","LOCAL SERVICE","NETWORK SERVICE", "ANONYMOUS LOGON", "UMFD-*")
| where match(GroupMembership, "Domain Admins")
| stats count
BY _time TargetUserName GroupMembership
BY _time Target_User_Name GroupMembership
action app dest
signature_id user vendor_product
| lookup domain_admins username as TargetUserName OUTPUT username
| lookup domain_admins username as Target_User_Name OUTPUT username
| fillnull value=NotDA username
| search username = "NotDA"
| `windows_domain_admin_impersonation_indicator_filter`
Expand All @@ -28,18 +28,18 @@ references:
- https://github.com/GhostPack/Rubeus/pull/136
- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4627
drilldown_searches:
- name: View the detection results for - "$TargetUserName$"
search: '%original_detection_search% | search TargetUserName = "$TargetUserName$"'
- name: View the detection results for - "$Target_User_Name$"
search: '%original_detection_search% | search Target_User_Name = "$Target_User_Name$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$TargetUserName$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$TargetUserName$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
- name: View risk events for the last 7 days for - "$Target_User_Name$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$Target_User_Name$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: 7d
latest_offset: "0"
finding:
title: $TargetUserName$ may be impersonating a Domain Administrator through a forged Kerberos ticket.
title: $Target_User_Name$ may be impersonating a Domain Administrator through a forged Kerberos ticket.
entity:
field: TargetUserName
field: Target_User_Name
type: user
score: 50
analytic_story:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Windows ESX Admins Group Creation Security Event
id: 53b4c927-5ec4-47cd-8aed-d4b303304f87
version: 9
version: 10
creation_date: '2024-07-30'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Michael Haag, Splunk
status: production
type: TTP
Expand All @@ -12,9 +12,9 @@ data_source:
- Windows Event Log Security 4730
- Windows Event Log Security 4737
search: |-
`wineventlog_security` EventCode IN (4727, 4730, 4737) (TargetUserName="ESX Admins" OR TargetUserName="*ESX Admins*")
`wineventlog_security` EventCode IN (4727, 4730, 4737) (Target_User_Name="ESX Admins" OR Target_User_Name="*ESX Admins*")
| stats count min(_time) as firstTime max(_time) as lastTime
BY EventCode TargetUserName TargetDomainName
BY EventCode Target_User_Name TargetDomainName
SubjectUserName SubjectDomainName Computer
| rename Computer as dest
| eval EventCodeDescription=case( EventCode=4727, "Security Enabled Global Group Created", EventCode=4730, "Security Enabled Global Group Deleted", EventCode=4737, "Security Enabled Global Group Modified" )
Expand Down
Loading
Loading