local_accounts_discovery
Description
Local accounts, System Owner/User discovery using operating systems utilities
Query · yara_l
events:
$process.metadata.event_type = "PROCESS_LAUNCH"
(
(
re.regex($process.target.process.file.full_path, `\\cmd\.exe$`) nocase and
strings.contains(strings.to_lower($process.target.process.command_line), " /c") and
strings.contains(strings.to_lower($process.target.process.command_line), "dir ") and
strings.contains(strings.to_lower($process.target.process.command_line), "\\users\\") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), " rmdir ")
)
or
(
re.regex($process.target.process.file.full_path, `\\net\.exe$`) nocase or
re.regex($process.target.process.file.full_path, `\\net1\.exe$`) nocase and
strings.contains(strings.to_lower($process.target.process.command_line), "user") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/domain") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/add") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/delete") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/active") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/expires") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/passwordreq") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/scriptpath") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/times") and
NOT strings.contains(strings.to_lower($process.target.process.command_line), "/workstations")
)
or
(
re.regex($process.target.process.file.full_path, `\\whoami\.exe$`) nocase or
re.regex($process.target.process.file.full_path, `\\quser\.exe$`) nocase or
re.regex($process.target.process.file.full_path, `\\qwinsta\.exe$`) nocase or
(
re.regex($process.target.process.file.full_path, `\\wmic\.exe$`) nocase and
strings.contains(strings.to_lower($process.target.process.command_line), "useraccount") and
strings.contains(strings.to_lower($process.target.process.command_line), "get")
) or
(
re.regex($process.target.process.file.full_path, `\\cmdkey\.exe$`) nocase and
strings.contains(strings.to_lower($process.target.process.command_line), " /l")
)
)
)
$process.principal.hostname = $hostname
match:
$hostname over 5m
outcome:
//example usage of specifying test user and hostname to adjust risk score
$risk_score = max(if($process.principal.user.userid = "user" and $process.principal.hostname = "hostname", 0, 15))
$principal_process_pid = array_distinct($process.principal.process.pid)
$principal_process_command_line = array_distinct($process.principal.process.command_line)
$principal_process_file_sha256 = array_distinct($process.principal.process.file.sha256)
$principal_process_file_full_path = array_distinct($process.principal.process.file.full_path)
$principal_process_product_specfic_process_id = array_distinct($process.principal.process.product_specific_process_id)
$principal_process_parent_process_product_specfic_process_id = array_distinct($process.principal.process.parent_process.product_specific_process_id)
$target_process_pid = array_distinct($process.target.process.pid)
$target_process_command_line = array_distinct($process.target.process.command_line)
$target_process_file_sha256 = array_distinct($process.target.process.file.sha256)
$target_process_file_full_path = array_distinct($process.target.process.file.full_path)
$target_process_product_specfic_process_id = array_distinct($process.target.process.product_specific_process_id)
$principal_user_userid = array_distinct($process.principal.user.userid)
$log_type = array_distinct(strings.concat($process.metadata.log_type,"/",$process.metadata.product_event_type))
condition:
$process