Vendor: SkySea
June 14, 2023 · View on GitHub
Product: ClientView
Use-Case: Lateral Movement
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 72 | 9 | 14 | 7 | 7 |
| Event Type | Rules | Models |
|---|---|---|
| app-activity | T1090.003 - Proxy: Multi-hop Proxy ↳ Auth-Tor-Shost: User authentication or login from a known TOR IP | |
| app-login | T1090.003 - Proxy: Multi-hop Proxy ↳ Auth-Tor-Shost: User authentication or login from a known TOR IP | |
| process-created | T1021.003 - T1021.003 ↳ A-Impacket-Lateral-Detection: Activity related to Impacket framework using wmiexec, dcomexe, or smbexec processes via command line have been found on this asset. ↳ A-PC-ParentName-ProcessName-DCOM-F: First time child process creation for DCOM associated process on this asset. ↳ A-PC-ParentName-ProcessName-DCOM-A: Abnormal child process creation for DCOM associated process on the asset. ↳ A-DCOMActivation-Known: Remote DCOM activation under DcomLaunch service on this asset. ↳ Impacket-Lateral-Detection: Activity related to Impacket framework using wmiexec, dcomexe, or smbexec processes via command line have been found. ↳ PC-ParentName-ProcessName-DCOM-F: First time child process creation for DCOM associated process ↳ PC-ParentName-ProcessName-DCOM-A: Abnormal child process creation for DCOM associated process. ↳ DCOMActivation-Known: Remote DCOM activation under DcomLaunch service T1210 - Exploitation of Remote Services ↳ A-Terminal-Svc-Proc-Spawn: Process spawned by the terminal service server on this asset. ↳ Terminal-Svc-Proc-Spawn: Process spawned by the terminal service server T1090 - Proxy ↳ A-Netsh-Port-Fwd: Netsh commands were used to configure port forwarding on this asset. ↳ Netsh-Port-Fwd: Netsh commands were used to configure port forwarding. T1021.001 - Remote Services: Remote Desktop Protocol ↳ A-Suspicious-RDP-TSCON: Suspicious usage of RDP using tscon.exe on this asset ↳ A-Netsh-RDP-Port-Fwd: Netsh commands used to configure port forwarding for port 3389, used for RDP, were detected on this asset. ↳ Suspicious-RDP-TSCON: Suspicious usage of RDP using tscon.exe ↳ Netsh-RDP-Port-Fwd: Netsh commands used to configure port forwarding for port 3389, used for RDP, were detected. T1047 - Windows Management Instrumentation ↳ A-Impacket-Lateral-Detection: Activity related to Impacket framework using wmiexec, dcomexe, or smbexec processes via command line have been found on this asset. ↳ Impacket-Lateral-Detection: Activity related to Impacket framework using wmiexec, dcomexe, or smbexec processes via command line have been found. T1021.006 - T1021.006 ↳ A-Remote-Powershell-Session: Remote Powershell session was detected by monitoring for wsmprovhost as a parent or child process on this asset. ↳ Remote-Powershell-Session: Remote Powershell session was detected by monitoring for wsmprovhost as a parent or child process. T1059.001 - Command and Scripting Interperter: PowerShell ↳ A-Remote-Powershell-Session: Remote Powershell session was detected by monitoring for wsmprovhost as a parent or child process on this asset. ↳ Remote-Powershell-Session: Remote Powershell session was detected by monitoring for wsmprovhost as a parent or child process. T1219 - Remote Access Software ↳ A-EPA-RAT-TSS: TeamViewer remote desktop access service started on this asset ↳ A-EPA-RAT-SSI: Splashtop remote desktop access service installed on this asset ↳ A-EPA-RAT-TI: TeamViewer remote desktop access agent installed on this asset ↳ A-EPA-RAT-SSS: Splashtop remote desktop access service started on this asset ↳ A-EPA-RAT-SI: Splashtop remote desktop access agent installed on this asset ↳ A-EPA-RAT-GSS: GoToMyPC remote desktop access service started on this asset ↳ A-EPA-RAT-GSI: GoToMyPC remote desktop access service installed on this asset ↳ A-EPA-RAT-TSI: TeamViewer remote desktop access service installed on this asset ↳ A-EPA-RAT-LSS: LogMeIn remote desktop access service started on this asset ↳ A-EPA-RAT-LSI: LogMeIn remote desktop access service installed on this asset ↳ A-EPA-RAT-LI: LogMeIn remote desktop access agent installed on this asset ↳ A-EPA-RAT-GI: GoToMyPC remote desktop access agent installed on this asset ↳ A-TSCON-LocalSystem: Tscon.exe was executed as Local System on this asset ↳ EPA-RAT-GSI: GoToMyPC remote desktop access service installed by this user ↳ EPA-RAT-LSS: LogMeIn remote desktop access service started by this user ↳ EPA-RAT-LI: LogMeIn remote desktop access agent installed by this user ↳ EPA-RAT-SSI: Splashtop remote desktop access service installed by this user ↳ EPA-RAT-SI: Splashtop remote desktop access agent installed by this user ↳ EPA-RAT-TSI: TeamViewer remote desktop access service installed by this user ↳ EPA-RAT-GI: GoToMyPC remote desktop access agent installed by this user ↳ EPA-RAT-TI: TeamViewer remote desktop access agent installed by this user ↳ EPA-RAT-GSS: GoToMyPC remote desktop access service started by this user ↳ EPA-RAT-TSS: TeamViewer remote desktop access service started by this user ↳ EPA-RAT-SSS: Splashtop remote desktop access service started by this user ↳ EPA-RAT-LSI: LogMeIn remote desktop access service installed by this user T1563.002 - T1563.002 ↳ A-TSCON-LocalSystem: Tscon.exe was executed as Local System on this asset | • PC-ParentName-ProcessName: Child processes created by a parent process • A-PC-ParentName-ProcessName: Processes for parent parent processes. |
| security-alert | T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools ↳ A-ALERT-DL: DL Correlation rule alert on asset ↳ A-ALERT-Correlation-Rule: Correlation rule alert on asset ↳ ALERT-Correlation-Rule: Correlation rule alert on asset accessed by this user ↳ ALERT-DL: DL Correlation rule alert on asset accessed by this user | |
| share-access | T1021.002 - Remote Services: SMB/Windows Admin Shares ↳ A-SA-OU-F: First admin share access to asset for this user in the organization ↳ A-SA-OU-A: Abnormal admin share access to asset for the user in the organization ↳ A-SA-OH-F: First admin share on asset for organization ↳ A-SA-OH-A: Abnormal admin share on asset in organization ↳ A-SA-ZH-F: First admin share on asset in the zone ↳ A-SA-ZH-A: Abnormal admin share on asset for zone ↳ A-SA-AsU-F: First access of admin share on asset ↳ A-SA-AsU-A: Abnormal access of admin share on the asset ↳ SA-OU-F: First admin share access for user in the organization ↳ SA-OU-A: Abnormal admin share access for user in the organization ↳ SA-OH-F: First admin share on this host ↳ SA-OH-A: Abnormal admin share on this host ↳ SA-AsU-F: First access of admin share on this host ↳ SA-AsU-A: Abnormal access of admin share on this host | • SA-AsU: Users accessing this Admin share • SA-OH: Assets on which admin share is accessed in organization • SA-OU: Users accessing admin share in the organization • A-SA-AsU: Users per Admin share • A-SA-ZH: Dest zones on which admin shares are accessed • A-SA-OH: Assets on which admin shares are accessed in organization • A-SA-OU: Admin Share users in organization |
| web-activity-allowed | T1071.001 - Application Layer Protocol: Web Protocols ↳ WEB-URank-Tor: User has accessed a tor-to-web proxy site T1090.003 - Proxy: Multi-hop Proxy ↳ A-NET-TOR-Outbound: Outbound connection to a known TOR IP ↳ A-WEB-TorProxy: Asset has accessed a known Tor web proxy ↳ A-WEB-UU-Tor: Asset has accessed a URL containing '/tor/server' ↳ WEB-UD-TorProxy: User has accessed a known Tor web proxy ↳ WEB-UI-Tor: User has accessed a known Tor exit node ↳ WEB-UU-Tor: User has accessed a URL containing '/tor/server' ↳ WEB-URank-Tor: User has accessed a tor-to-web proxy site T1190 - Exploit Public Fasing Application ↳ A-NET-Log4j-IP: Asset was accessed by an external IP associated with Log4j exploit | |
| web-activity-denied | T1071.001 - Application Layer Protocol: Web Protocols ↳ WEB-URank-Tor: User has accessed a tor-to-web proxy site T1090.003 - Proxy: Multi-hop Proxy ↳ A-NETF-TOR-Outbound: Outbound failed connection to a known TOR IP ↳ A-WEB-TorProxy: Asset has accessed a known Tor web proxy ↳ A-WEB-UU-Tor: Asset has accessed a URL containing '/tor/server' ↳ WEB-UD-TorProxy: User has accessed a known Tor web proxy ↳ WEB-UI-Tor: User has accessed a known Tor exit node ↳ WEB-UU-Tor: User has accessed a URL containing '/tor/server' ↳ WEB-URank-Tor: User has accessed a tor-to-web proxy site T1190 - Exploit Public Fasing Application ↳ A-NETF-Log4j-IP: There was a failed attempt to access this asset by an external IP associated with Log4j exploit |