Techniques
Sample rules
Windows Access Token Manipulation Winlogon Duplicate Token Handle
- source: splunk
- technicques:
Description
The following analytic detects a process requesting duplicate-handle and query-limited-information access to winlogon.exe. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
Detection logic
`sysmon`
EventCode=10
TargetImage="*:\\Windows\\system32\\winlogon.exe"
NOT SourceImage IN (
"C:\\Windows\\system32\\LogonUI.exe",
"C:\\Windows\\system32\\lsass.exe",
"C:\\Windows\\system32\\smss.exe",
"C:\\Windows\\system32\\svchost.exe",
"C:\\Windows\\system32\\wbem\\wmiprvse.exe"
)
Convert GrantedAccess from hexadecimal to decimal. 0x1040 combines PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_DUP_HANDLE = 64
| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096
| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)
| where duplicate_handle_set == PROCESS_DUP_HANDLE
AND query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product
| eval CallTrace=split(CallTrace, "
|")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_access_token_manipulation_winlogon_duplicate_token_handle_filter`
Windows Access Token Winlogon Duplicate Handle In Uncommon Path
- source: splunk
- technicques:
Description
The following analytic detects duplicate-handle and query-limited-information access to winlogon.exe from an uncommon or public source path. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
Detection logic
`sysmon`
EventCode=10
TargetImage="*:\\Windows\\System32\\winlogon.exe"
NOT SourceImage IN (
"%SystemRoot%\\*",
"C:\\Program Files (x86)\\*",
"C:\\Program Files\\*",
"C:\\Windows\\*"
)
Convert GrantedAccess from hexadecimal to decimal. 0x1040 combines PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_DUP_HANDLE = 64
| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096
| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)
| where duplicate_handle_set == PROCESS_DUP_HANDLE
AND query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product
| eval CallTrace=split(CallTrace, "
|")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_access_token_winlogon_duplicate_handle_in_uncommon_path_filter`