Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add RDP Logon/Logoff/Reconnect sample evtx #3

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

fukusuket
Copy link
Contributor

@fukusuket fukusuket commented Nov 22, 2024

What Changed

I have created a sample evtx for RDP Logon/Logoff/Reconnect that hits the following rules.
(For implementation Yamato-Security/takajo#209)

I would appreciate it if you could check it out when you have time🙏

@fukusuket
Copy link
Contributor Author

fukusuket commented Nov 22, 2024

./hayabusa-2.19.0-mac-aarch64 csv-timeline -f ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx -w -e informational --include-eid 21,22,23,24,25 -s -p super-verbose -q
....

Scanning finished.

Timestamp · RuleTitle · Level · Computer · Channel · EventID · RuleAuthor · RuleModifiedDate · Status · RecordID · Details · ExtraFieldInfo · MitreTactics · MitreTags · OtherTags · Provider · RuleCreationDate · RuleFile · EvtxFile
2024-11-23 07:36:23.634 +09:00 · RDP Logon · info · EC2AMAZ-3NFFVNI · RDS-LSM · 21 · Zach Mathis · 2024/11/10 · stable · 2300 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 2 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_21_Info_RDP-Logon.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:37:06.706 +09:00 · RDP Disconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 24 · Zach Mathis · 2024/11/10 · stable · 2303 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 2 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_24_Info_RDP-Disconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:37:46.948 +09:00 · RDP Reconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 25 · Fukusuke Takahashi · 2024/11/10 · test · 2305 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 2 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2024/11/03 · LocalSessManager_25_Info_RDP-Reconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:38:40.369 +09:00 · RDP Logoff · info · EC2AMAZ-3NFFVNI · RDS-LSM · 23 · Zach Mathis · 2024/11/10 · stable · 2306 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 2 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_23_Info_RDP-Logoff.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:38:40.988 +09:00 · RDP Disconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 24 · Zach Mathis · 2024/11/10 · stable · 2308 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 2 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_24_Info_RDP-Disconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:39:20.505 +09:00 · RDP Logon · info · EC2AMAZ-3NFFVNI · RDS-LSM · 21 · Zach Mathis · 2024/11/10 · stable · 2311 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 3 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_21_Info_RDP-Logon.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:45:55.461 +09:00 · RDP Logoff · info · EC2AMAZ-3NFFVNI · RDS-LSM · 23 · Zach Mathis · 2024/11/10 · stable · 2313 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 3 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_23_Info_RDP-Logoff.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:45:56.076 +09:00 · RDP Disconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 24 · Zach Mathis · 2024/11/10 · stable · 2315 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 3 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_24_Info_RDP-Disconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:47:31.548 +09:00 · RDP Logon · info · EC2AMAZ-3NFFVNI · RDS-LSM · 21 · Zach Mathis · 2024/11/10 · stable · 2318 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 4 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_21_Info_RDP-Logon.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:48:01.842 +09:00 · RDP Disconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 24 · Zach Mathis · 2024/11/10 · stable · 2321 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 4 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_24_Info_RDP-Disconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:48:31.312 +09:00 · RDP Reconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 25 · Fukusuke Takahashi · 2024/11/10 · test · 2323 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 4 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2024/11/03 · LocalSessManager_25_Info_RDP-Reconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:48:45.955 +09:00 · RDP Logoff · info · EC2AMAZ-3NFFVNI · RDS-LSM · 23 · Zach Mathis · 2024/11/10 · stable · 2324 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 4 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_23_Info_RDP-Logoff.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:48:46.587 +09:00 · RDP Disconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 24 · Zach Mathis · 2024/11/10 · stable · 2326 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 4 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_24_Info_RDP-Disconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:49:00.168 +09:00 · RDP Logon · info · EC2AMAZ-3NFFVNI · RDS-LSM · 21 · Zach Mathis · 2024/11/10 · stable · 2329 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 5 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_21_Info_RDP-Logon.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:49:16.732 +09:00 · RDP Logoff · info · EC2AMAZ-3NFFVNI · RDS-LSM · 23 · Zach Mathis · 2024/11/10 · stable · 2331 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 5 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_23_Info_RDP-Logoff.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:49:17.027 +09:00 · RDP Disconnect · info · EC2AMAZ-3NFFVNI · RDS-LSM · 24 · Zach Mathis · 2024/11/10 · stable · 2333 · TgtUser: EC2AMAZ-3NFFVNI\samurai ¦ SessID: 5 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_24_Info_RDP-Disconnect.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

2024-11-23 07:50:25.445 +09:00 · RDP Logon · info · EC2AMAZ-3NFFVNI · RDS-LSM · 21 · Zach Mathis · 2024/11/10 · stable · 2336 · TgtUser: EC2AMAZ-3NFFVNI\Administrator ¦ SessID: 6 ¦ SrcIP: 219.100.37.234 · - ·  ·  · RDP ¦ attack.lateral_movement · RDS-LSM · 2022/12/07 · LocalSessManager_21_Info_RDP-Logon.yml · ../rdp/Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx

Rule Authors:

╭──────────────────────────────────────────╮
│ Zach Mathis (3)   Fukusuke Takahashi (1) │
╰─────────────────╌────────────────────────╯

Results Summary:

Events with hits / Total events: 17 / 76 (Data reduction: 59 events (77.63%))

Total | Unique detections: 17 | 4
Total | Unique critical detections: 0 (0.00%) | 0 (0.00%)
Total | Unique high detections: 0 (0.00%) | 0 (100.00%)
Total | Unique medium detections: 0 (0.00%) | 0 (0.00%)
Total | Unique low detections: 0 (0.00%) | 0 (0.00%)
Total | Unique informational detections: 17 (100.00%) | 4 (0.00%)

Dates with most total detections:
critical: n/a, high: n/a, medium: n/a, low: n/a, informational: 2024-11-23 (17)

Top 5 computers with most unique detections:
critical: n/a
high: n/a
medium: n/a
low: n/a
informational: EC2AMAZ-3NFFVNI (4)

╭──────────────────────────────────────────────╮
│ Top critical alerts:        Top high alerts: │
├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
│ n/a                         n/a              │
│ n/a                         n/a              │
│ n/a                         n/a              │
│ n/a                         n/a              │
│ n/a                         n/a              │
├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
│ Top medium alerts:          Top low alerts:  │
├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
│ n/a                         n/a              │
│ n/a                         n/a              │
│ n/a                         n/a              │
│ n/a                         n/a              │
│ n/a                         n/a              │
├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
│ Top informational alerts:                    │
├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
│ RDP Disconnect (6)          n/a              │
│ RDP Logon (5)               n/a              │
│ RDP Logoff (4)              n/a              │
│ RDP Reconnect (2)           n/a              │
│ n/a                         n/a              │
╰───────────────────────────╌──────────────────╯

@fukusuket fukusuket changed the title add RDP logon/logoff/reconnect sample evtx add RDP Logon/Logoff/Reconnect sample evtx Nov 22, 2024
@fukusuket fukusuket changed the title add RDP Logon/Logoff/Reconnect sample evtx Add RDP Logon/Logoff/Reconnect sample evtx Nov 23, 2024
@fukusuket
Copy link
Contributor Author

@YamatoSecurity
I forgot to mentions it! I would appreciate it if you could check it out when you have time🙏

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant