Splunk Search

Do we have any Tarrask Malware detection queries for Splunk Enterprise?

Tomu521
New Member

Do we have any Tarrask Malware detection queries for Splunk Enterprise? 

Labels (3)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Tomu521 - You can use Sysmon to monitor the registry and then create an alert based on that.

 

I'm giving a solution based on this blog:

VatsalJagani_0-1650956111484.png

 

I would suggest also exploring the solution given by @Azeemering , as that will not require to install Sysmon.

 

I hope this helps!! Upvote/Karma would be appreciated!!!

Tomu521
New Member

@VatsalJagani Huge help. Big Thanks. 

0 Karma

Azeemering
Builder

Modify your audit policy to identify Scheduled Tasks actions by enabling logging “TaskOperational” within Microsoft-Windows-TaskScheduler/Operational. Apply the recommended Microsoft audit policy settings suitable to your environment.

Enable and centralize the following Task Scheduler logs. Even if the tasks are ‘hidden’, these logs track key events relating to them that could lead you to discovering a well-hidden persistence mechanism
Event ID 4698 within the Security.evtx log
Microsoft-Windows-TaskScheduler/Operational.evtx log

The threat actors in this campaign used hidden scheduled tasks to maintain access to critical assets exposed to the internet by regularly re-establishing outbound communications with C&C infrastructure. Remain vigilant and monitor uncommon behavior of your outbound communications by ensuring that monitoring and alerting for these connections from these critical Tier 0 and Tier 1 assets is in place.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...