Skip to content

Investigations (BOTS)

End-to-end walkthroughs against the public Boss of the SOC datasets. Each is a chain of searches that follows one scenario, so it works as practice for the technique as much as a reference.

Brute Force Password Investigation (BOTS v1)

Working a credential brute force against a web login, from detecting it to recovering the password and timing the successful login.

Find the brute forcing against the target:

sourcetype=stream:http dest="<IP address receiving the request>" http_method=POST

Group attempts by source and submitted credentials:

index=botsv1 sourcetype=stream:http form_data=*username*passwd*
| stats count BY src, form_data, timestamp

Extract the password field and measure the average attempt length:

index="botsv1" sourcetype=stream:http form_data=*username*passwd*
| rex field=form_data "&passwd=(?<password>[\w\d]+)&"
| eval lenpword=len(password)
| stats avg(lenpword) as avglen

Count the number of distinct passwords tried:

index="botsv1" sourcetype=stream:http form_data=*username*passwd*
| rex field=form_data "&passwd=(?<password>[\w\d]+)&"

Confirm the password that worked and when it was used:

index="botsv1" sourcetype=stream:http form_data=*username*passwd*
| rex field=form_data "&passwd=(?<password>[\w\d]+)&"
| search password = "batman"

Look for a successful login from a different IP to confirm account takeover:

index=botsv1 sourcetype=stream:http form_data=*username*passwd*
| stats count BY src, form_data, timestamp

Ransomware / Host Compromise Investigation (BOTS v1)

Following a compromised host (we8105desk) through delivery, execution, and encryption of files.

Resolve the hostname to an IP:

index="botsv1" we8105desk
| stats count by src_ip

Find the file server shares the host touched:

index="botsv1" sourcetype="stream:smb" src_ip=192.168.250.100
| stats count by path

Count PDFs encrypted on the file server:

index="botsv1" .pdf
| stats dc(Relative_Target_Name)

Count encrypted .txt files for a specific user:

index="botsv1" sourcetype="xmlwineventlog:microsoft-windows-sysmon/operational" .txt bob.smith TargetFilename="C:\\Users\\bob.smith.WAYNECORPINC\\Desktop\\*"
| stats dc(TargetFilename)

The same investigation also uses the shared detections on the Detections page: domains the host contacted, VBScript execution, USB insertion, and the hash of the dropped executable.