Detection: LOLBAS With Network Traffic

REMOVED DETECTION

This detection has been removed from the Splunk Threat Research content library and is no longer maintained or supported.

Reason: Detection deprecated due to high false positive rates from certain LOLBAS binaries with common legitimate network behavior. This broad analytic is being split into more manageable anomaly analytics with separate process groups and common-port tuning.

Removed in version: 6.8.0

Replacement: LOLBAS Network Connection On Uncommon Port

Replacement: LOLBAS Rare Network Connection

If you have any questions or concerns, please reach out to us at research@splunk.com.

Description

The following analytic identifies the use of Living Off the Land Binaries and Scripts (LOLBAS) with network traffic. It leverages data from the Network Traffic data model to detect when native Windows binaries, often abused by adversaries, initiate network connections. This activity is significant as LOLBAS are frequently used to download malicious payloads, enabling lateral movement, command-and-control, or data exfiltration. If confirmed malicious, this behavior could allow attackers to execute arbitrary code, escalate privileges, or maintain persistence within the environment, posing a severe threat to organizational security.

 1
 2| tstats `security_content_summariesonly`
 3  count min(_time) as firstTime
 4        max(_time) as lastTime
 5from datamodel=Network_Traffic.All_Traffic where
 6All_Traffic.app IN (
 7    "*\\At.exe",
 8    "*\\Atbroker.exe",
 9    "*\\Bash.exe",
10    "*\\Bitsadmin.exe",
11    "*\\Certoc.exe",
12    "*\\certutil.exe",
13    "*\\cmd.exe",
14    "*\\Cmstp.exe",
15    "*\\cscript.exe",
16    "*\\Diskshadow.exe",
17    "*\\Dnscmd.exe",
18    "*\\Extexport.exe",
19    "*\\Forfiles.exe",
20    "*\\Ftp.exe",
21    "*\\Gpscript.exe",
22    "*\\Hh.exe",
23    "*\\Ie4uinit.exe",
24    "*\\Ieexec.exe",
25    "*\\Infdefaultinstall.exe",
26    "*\\Installutil.exe",
27    "*\\makecab.exe",
28    "*\\Mavinject.exe",
29    "*\\Microsoft.Workflow.Compiler.exe",
30    "*\\Msbuild.exe",
31    "*\\Msconfig.exe",
32    "*\\Msdt.exe",
33    "*\\Mshta.exe",
34    "*\\Msiexec.exe",
35    "*\\Netsh.exe",
36    "*\\notepad.exe",
37    "*\\Odbcconf.exe",
38    "*\\OfflineScannerShell.exe",
39    "*\\Pcalua.exe",
40    "*\\Pcwrun.exe",
41    "*\\Pnputil.exe",
42    "*\\powershell_ise.exe",
43    "*\\powershell.exe",
44    "*\\Presentationhost.exe",
45    "*\\pwsh.exe",
46    "*\\Rasautou.exe",
47    "*\\Regasm.exe",
48    "*\\Register-cimprovider.exe",
49    "*\\Regsvcs.exe",
50    "*\\Regsvr32.exe",
51    "*\\Runonce.exe",
52    "*\\Runscripthelper.exe",
53    "*\\Schtasks.exe",
54    "*\\Scriptrunner.exe",
55    "*\\SettingSyncHost.exe",
56    "*\\Stordiag.exe",
57    "*\\Syncappvpublishingserver.exe",
58    "*\\Ttdinject.exe",
59    "*\\Tttracer.exe",
60    "*\\Verclsid.exe",
61    "*\\Wab.exe",
62    "*\\Wmic.exe",
63    "*\\WorkFolders.exe",
64    "*\\Wuauclt.exe",
65    "*\\Xwizard.exe"
66    )
67
68NOT All_Traffic.dest_ip IN (
69        "10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16", "100.64.0.0/10",
70        "127.0.0.0/8", "169.254.0.0/16", "192.0.0.0/24", "192.0.0.0/29", "192.0.0.8/32",
71        "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
72        "192.31.196.0/24", "192.52.193.0/24", "192.88.99.0/24", "224.0.0.0/4", "192.175.48.0/24",
73        "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4"
74        )
75
76by All_Traffic.action All_Traffic.app All_Traffic.dest All_Traffic.dest_ip All_Traffic.dest_port
77   All_Traffic.direction All_Traffic.dvc All_Traffic.protocol All_Traffic.protocol_version
78   All_Traffic.src All_Traffic.src_ip All_Traffic.src_port All_Traffic.transport All_Traffic.user
79   All_Traffic.vendor_product
80
81
82| `drop_dm_object_name(All_Traffic)`
83
84| `security_content_ctime(firstTime)`
85
86| `security_content_ctime(lastTime)`
87
88| rex field=app ".*\\\(?<process_name>.*)$"
89
90| `lolbas_with_network_traffic_filter`

Data Source

Name Platform Sourcetype Source
Sysmon EventID 3 Windows icon Windows 'XmlWinEventLog' 'XmlWinEventLog:Microsoft-Windows-Sysmon/Operational'

Macros Used

Name Value
security_content_summariesonly summariesonly=summariesonly_config allow_old_summaries=oldsummaries_config fillnull_value=fillnull_config``
lolbas_with_network_traffic_filter ``
lolbas_with_network_traffic_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.

Annotations

- MITRE ATT&CK
+ Kill Chain Phases
+ NIST
+ CIS
- Threat Actors
ID Technique Tactic

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule N/A
Earliest Time N/A
Latest Time N/A
Schedule Window N/A
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) No
TTP detections generate a Finding (Notable) and may generate Intermediate Findings (Risk Events) for associated entities.

Implementation

To successfully implement this detection you must ingest events into the Network traffic data model that contain the source, destination, and communicating process in the app field. Relevant processes must also be ingested in the Endpoint data model with matching process_id field. Sysmon EID1 and EID3 are good examples of this type this data type.

Known False Positives

Legitimate usage of internal automation or scripting, especially powershell.exe or pwsh.exe, internal to internal or logon scripts. It may be necessary to omit internal IP ranges if extremely noisy. ie NOT dest_ip IN ("10.0.0.0/8","172.16.0.0/12","192.168.0.0/16","170.98.0.0/16","0:0:0:0:0:0:0:1")

Associated Analytic Story

No associated analytic story

References

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation Not Applicable N/A N/A N/A
Unit Not Applicable N/A N/A N/A
Integration Not Applicable N/A N/A N/A

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 19