-
Notifications
You must be signed in to change notification settings - Fork 525
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution #3545
Conversation
rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml
Show resolved
Hide resolved
rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml
Show resolved
Hide resolved
rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great work 👍🏽
Nothing that I can find to tune FPs out, simply because we are looking for legitimate signed RMM.
rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Make sure to resolve @Samirbous's comment, prior to merging - but from my point of view LGTM.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
we need to compensate with one for sysmon/4688 based on process.name
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍
rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml
Outdated
Show resolved
Hide resolved
…t_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I agree with narrowing the index patterns, LGTM
rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml
Show resolved
Hide resolved
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
…ution (#3545) * [Rule Tuning] First Time Seen Commonly Abused Remote Access Tool Execution * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update command_and_control_new_terms_commonly_abused_rat_execution.toml * Update rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> (cherry picked from commit 4ab7c9b)
Issues
Resolves #3518
Summary
Updates the rule with more signers and processes from https://github.com/redcanaryco/surveyor/blob/master/definitions/remote-admin.json and telem.
Also (trying to) contributed back to the reference: redcanaryco/surveyor#160