Name:Executables Or Script Creation In Temp Path id:e0422b71-2c05-4f32-8754-01fb415f49c9 version:11 date:2025-02-11 author:Teoderick Contreras, Splunk status:production type:Anomaly Description:The following analytic identifies the creation of executables or scripts in suspicious file paths on Windows systems. It leverages the Endpoint.Filesystem data model to detect files with specific extensions (e.g., .exe, .dll, .ps1) created in uncommon directories (e.g., \windows\fonts\, \users\public\). This activity is significant as adversaries often use these paths to evade detection and maintain persistence. If confirmed malicious, this behavior could allow attackers to execute unauthorized code, escalate privileges, or persist within the environment, posing a significant security threat. Data_source:
-Sysmon EventID 11
search:| tstats `security_content_summariesonly` values(Filesystem.file_path) as file_path count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where Filesystem.file_name IN ("*.exe", "*.dll", "*.sys", "*.com", "*.vbs", "*.vbe", "*.js", "*.ps1", "*.bat", "*.cmd", "*.pif") AND Filesystem.file_path IN ("*\\AppData\\Local\\Temp\\*", "*:\\Windows\\Temp\\*", "*:\\Temp*") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.user | `drop_dm_object_name(Filesystem)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `executables_or_script_creation_in_temp_path_filter`
how_to_implement:To successfully implement this search you need to be ingesting information on process that include the name of the Filesystem responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Filesystem` node. known_false_positives:Administrators may allow creation of script or exe in the paths specified. Filter as needed. References: -https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ -https://twitter.com/pr0xylife/status/1590394227758104576 -https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ drilldown_searches: name:'View the detection results for - "$user$"' search:'%original_detection_search% | search user = "$user$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$user$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' tags: analytic_story: - 'Chaos Ransomware' - 'Trickbot' - 'Snake Keylogger' - 'CISA AA23-347A' - 'Industroyer2' - 'WinDealer RAT' - 'Qakbot' - 'Warzone RAT' - 'IcedID' - 'ValleyRAT' - 'Azorult' - 'Handala Wiper' - 'LockBit Ransomware' - 'Meduza Stealer' - 'Brute Ratel C4' - 'AsyncRAT' - 'AcidPour' - 'Derusbi' - 'DarkGate Malware' - 'Graceful Wipe Out Attack' - 'NjRAT' - 'WhisperGate' - 'Data Destruction' - 'BlackByte Ransomware' - 'AgentTesla' - 'Swift Slicer' - 'Crypto Stealer' - 'Hermetic Wiper' - 'MoonPeak' - 'Double Zero Destructor' - 'XMRig' - 'PlugX' - 'Amadey' - 'DarkCrystal RAT' - 'Remcos' - 'China-Nexus Threat Activity' - 'Earth Estries' - 'Rhysida Ransomware' - 'RedLine Stealer' - 'Volt Typhoon' - 'SnappyBee' asset_type:Endpoint mitre_attack_id: - 'T1036' product: - 'Splunk Enterprise' - 'Splunk Enterprise Security' - 'Splunk Cloud' security_domain:endpoint