Skip to content

Detections

Reusable detection searches for authentication, network, malware, log integrity, and operational monitoring.

Authentication and Accounts

New local admin accounts

Correlates a new account (4720) with its addition to a security group (4732) in the same window.

index=win_servers sourcetype=windows:security EventCode=4720 OR (EventCode=4732 Administrators)
| transaction Security_ID maxspan=180m
| search EventCode=4720 EventCode=4732
| table _time, EventCode, Security_ID, SamAccountName

Event IDs: 4720 new user created, 4732 user added to security group, 4624 successful logon.

Interactive logins from service accounts

Service accounts (svc_*) should not log on interactively.

index=systems sourcetype=audit_logs user=svc_*
| table _time dest user

Outlier interactive logins from service accounts

Flags service-account logins first seen in the last day.

index=systems sourcetype=audit_logs user=svc_*
| stats earliest(_time) as earliest latest(_time) as latest by user, dest
| eval isOutlier=if(earliest >= relative_time(now(), "-1d@d"), 1, 0)
| convert ctime(earliest) ctime(latest)
| where isOutlier=1

Brute force attempts

Accounts with at least one success and more than 100 failures.

index=* sourcetype=win*security user=* user!=""
| stats count(eval(action="success")) as successes count(eval(action="failure")) as failures by user, ComputerName
| where successes>0 AND failures>100

Network and Scanning

Network and port scanning

One source touching many ports or hosts.

index=* sourcetype=firewall*
| stats dc(dest_port) as num_dest_port dc(dest_ip) as num_dest_ip by src_ip
| where num_dest_port >500 OR num_dest_ip > 500

Internal scanning is more concerning than external.

Basic TOR detection

index=network sourcetype=firewall_data app=tor src_ip=*
| table _time src_ip src_port dest_ip dest_port bytes app

Unencrypted communications to a sensitive app

Traffic to an app on a non-TLS port.

index=* sourcetype=firewall_data dest_port!=443 app=workday*
| table _time user app bytes* src_ip dest_ip dest_port

Large web uploads

Possible exfiltration.

index=* sourcetype=websense*
| where bytes_out > 35000000
| table _time src_ip bytes* uri

Web users by country

index=web sourcetype=access_combined
| iplocation clientip
| stats dc(clientip) by Country

Web users by country on a map

index=web sourcetype=access_combined
| iplocation clientip
| geostats dc(clientip) by Country

Malware and Log Integrity

Recurring malware on a host

Malware seen repeatedly over a time range (same detection firing again and again).

index=* sourcetype=symantec:*
| stats count range(_time) as TimeRange by Risk_Name, Computer_Name
| where TimeRange>1800
| eval TimeRange_In_Hours = round(TimeRange/3600,2), TimeRange_In_Days = round (TimeRange/3600/24,2)

Windows audit log tampering

Log clearing and audit service shutdown.

index=* (sourcetype=wineventlog AND (EventCode=1102 OR EventCode=1100)) OR (sourcetype=wineventlog AND EventCode=104)
| stats count by _time EventCode Message sourcetype host

Event IDs: 1102 security log cleared, 1100 event logging service shut down, 104 event log cleared.

Domains contacted by a host

Strips common benign domains to surface the rest.

index="botsv1" src_ip="192.168.250.100" source="stream:dns" NOT query=*.local AND NOT query=*.arpa AND NOT query=*.microsoft.com AND query=*.*
| table _time, query
| sort by _time desc

VBScript execution (Sysmon)

index="botsv1" sourcetype="xmlwineventlog:microsoft-windows-sysmon/operational" *.vbs
| eval cmdlen=len(CommandLine)
| table _time, CommandLine, cmdlen

USB device insertion

index="botsv1" sourcetype=winregistry friendlyname

Hash of an executable (Sysmon)

index="botsv1" 3791.exe md5 sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" CommandLine="3791.exe"

Operations and Performance

List all sourcetypes in an index

index="botsv3"
| stats count by sourcetype

Windows security event codes present

index=win_servers sourcetype=windows:security
| table EventCode
| tstats prestats=t count WHERE index=apps by host _time span=1m
| timechart partial=f span=1m count by host limit=0

Memory utilization by host

index=main sourcetype=vmstat
| timechart max(memUsedPct) by host

Hosts over 80% memory

index=main sourcetype=vmstat
| stats max(memUsedPct) as memused by host
| where memused>80

Convert bytes to MB

index=botsv3 earliest=0 frothlywebcode "*.tar.gz" operation="REST.PUT.OBJECT" http_status=200
| table object_size
| eval mb=round(object_size/1024/1024,2)