Threat Hunting Queries Pack (Elastic + Splunk + Sigma)
Threat Hunting Queries Pack (Elastic + Splunk + Sigma)
This pack provides ready‑to‑use Threat Hunting Queries for Elastic (KQL), Splunk (SPL), and Sigma (YAML). These queries target common adversary behaviors across MITRE ATT&CK: PowerShell abuse, credential access, lateral movement, beaconing, and defense evasion.
🔥 Elastic / Kibana (KQL)
Suspicious PowerShell (Encoded Commands / Download)
process.name: "powershell.exe" and ( process.command_line: "*-EncodedCommand*" or process.command_line: "*DownloadString*" or process.command_line: "*IEX*" )
LSASS Access (Credential Theft)
process.name: ("procdump.exe", "rundll32.exe", "powershell.exe") and
process.command_line: "*lsass*" and
not process.parent.name: "taskmgr.exe"
Lateral Movement (SMB / RDP)
network.protocol: ("smb", "rdp") and
event.action: "connection_attempt" and
network.direction: "outbound"
C2 Beaconing (Low‑and‑Slow)
network.direction: "outbound" and bytes_out < 2000 and destination.port: (80, 443, 8080) and network.transport: "tcp"
🔵 Splunk (SPL)
Suspicious PowerShell Execution
index=security sourcetype=WinEventLog:Security OR sourcetype=Sysmon Image="*\\powershell.exe" | search CommandLine="*-EncodedCommand*" OR CommandLine="*DownloadString*" OR CommandLine="*IEX*"
LSASS Dump Attempt
index=security sourcetype=Sysmon Image="*\\procdump.exe" OR Image="*\\rundll32.exe" OR Image="*\\powershell.exe" CommandLine="*lsass*" | where NOT like(ParentImage, "%taskmgr.exe")
Lateral Movement (RDP / SMB)
index=network sourcetype="zeek_conn" OR sourcetype="suricata" (dest_port=3389 OR dest_port=445 OR dest_port=139) | stats count by src_ip dest_ip dest_port | where count > 10
C2 Beaconing Detection
index=network sourcetype="zeek_conn" | stats count, avg(duration) by src_ip dest_ip dest_port | where count > 50 AND avg(duration < 60)
🧩 Sigma Rules (YAML)
Sigma: Suspicious PowerShell Encoded Command
title: Suspicious PowerShell Encoded Command
id: 0001-TH-Powershell-Encoded
status: experimental
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains:
- '-EncodedCommand'
- 'DownloadString'
- 'IEX'
condition: selection
level: high
Sigma: LSASS Access by Non‑System Tool
title: LSASS Access by Non-System Tool
id: 0002-TH-LSASS-Access
status: experimental
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains: 'lsass'
Image|endswith:
- '\procdump.exe'
- '\rundll32.exe'
- '\powershell.exe'
filter_legit:
ParentImage|endswith: '\taskmgr.exe'
condition: selection and not filter_legit
level: high
Sigma: RDP Lateral Movement Spike
title: RDP Lateral Movement Spike
id: 0003-TH-RDP-Lateral
status: experimental
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType: 10
condition: selection
level: medium
✔ Final Thoughts
This Threat Hunting Queries Pack gives SOC analysts and DFIR responders a powerful set of ready‑to‑deploy detection queries across Elastic, Splunk, and Sigma. Use these queries to hunt for adversary behaviors, validate hypotheses, and strengthen your detection engineering pipeline.
Comments
Post a Comment
Drop your thoughts below — no noise, no spam, just signal.