Name:Windows Handle Duplication in Known UAC-Bypass Binaries id:d7369bf5-1315-4138-b927-2dd8bb8c1da7 version:5 date:None author:Teoderick Contreras, Splunk status:production type:Anomaly Description:The following analytic detects duplicate-handle access to known UAC-bypass binaries from a non-standard source path.
It leverages Sysmon EventCode 10, converts GrantedAccess from hexadecimal, and checks for PROCESS_DUP_HANDLE. Data_source:
how_to_implement:To successfully implement this search, you must be ingesting data that records process activity from your hosts to populate the endpoint data model in the processes node. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. known_false_positives:It is possible legitimate applications will request access to list of know abused Windows UAC binaries process, filter as needed. References: -https://www.recordedfuture.com/research/from-castleloader-to-castlerat-tag-150-advances-operations drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Castle RAT']