Techniques
Sample rules
Windows TeamCity Payload Execution from Temp Directory
- source: splunk
- technicques:
- T1190
- T1505.003
- T1059
Description
Detects the bundled TeamCity java executing a payload out of the temp directory. This activity can be associated with a malicious plugin installed by metasploit for remote code execution.
Detection logic
| tstats `security_content_summariesonly`
count min(_time) as firstTime
max(_time) as lastTime
from datamodel=Endpoint.Processes where
Processes.process="*-classpath *"
Processes.process="*:\\Windows\\TEMP\\~spawn*"
Processes.process="*.tmp.dir *"
Processes.process="*.Payload*"
Processes.process="*TeamCity*"
by Processes.process Processes.vendor_product Processes.user_id Processes.process_hash
Processes.parent_process_name Processes.parent_process_exec Processes.action
Processes.dest Processes.process_current_directory Processes.process_path
Processes.process_integrity_level Processes.original_file_name
Processes.parent_process Processes.parent_process_path
Processes.parent_process_guid Processes.parent_process_id
Processes.process_guid Processes.process_id
Processes.user Processes.process_name
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_teamcity_payload_execution_from_temp_directory_filter`