Threat Hunting Queries Pack (Elastic + Splunk + Sigma)

Threat Hunting Queries Pack (Elastic + Splunk + Sigma)

This pack provides ready‑to‑use Threat Hunting Queries for Elastic (KQL), Splunk (SPL), and Sigma (YAML). These queries target common adversary behaviors across MITRE ATT&CK: PowerShell abuse, credential access, lateral movement, beaconing, and defense evasion.


🔥 Elastic / Kibana (KQL)

Suspicious PowerShell (Encoded Commands / Download)

process.name: "powershell.exe" and (
  process.command_line: "*-EncodedCommand*" or
  process.command_line: "*DownloadString*" or
  process.command_line: "*IEX*"
)
  

LSASS Access (Credential Theft)

process.name: ("procdump.exe", "rundll32.exe", "powershell.exe") and
process.command_line: "*lsass*" and
not process.parent.name: "taskmgr.exe"
  

Lateral Movement (SMB / RDP)

network.protocol: ("smb", "rdp") and
event.action: "connection_attempt" and
network.direction: "outbound"
  

C2 Beaconing (Low‑and‑Slow)

network.direction: "outbound" and
bytes_out < 2000 and
destination.port: (80, 443, 8080) and
network.transport: "tcp"
  

🔵 Splunk (SPL)

Suspicious PowerShell Execution

index=security sourcetype=WinEventLog:Security OR sourcetype=Sysmon
Image="*\\powershell.exe"
| search CommandLine="*-EncodedCommand*" OR CommandLine="*DownloadString*" OR CommandLine="*IEX*"
  

LSASS Dump Attempt

index=security sourcetype=Sysmon
Image="*\\procdump.exe" OR Image="*\\rundll32.exe" OR Image="*\\powershell.exe"
CommandLine="*lsass*"
| where NOT like(ParentImage, "%taskmgr.exe")
  

Lateral Movement (RDP / SMB)

index=network sourcetype="zeek_conn" OR sourcetype="suricata"
(dest_port=3389 OR dest_port=445 OR dest_port=139)
| stats count by src_ip dest_ip dest_port
| where count > 10
  

C2 Beaconing Detection

index=network sourcetype="zeek_conn"
| stats count, avg(duration) by src_ip dest_ip dest_port
| where count > 50 AND avg(duration < 60)
  

🧩 Sigma Rules (YAML)

Sigma: Suspicious PowerShell Encoded Command

title: Suspicious PowerShell Encoded Command
id: 0001-TH-Powershell-Encoded
status: experimental
logsource:
  product: windows
  category: process_creation

detection:
  selection:
    Image|endswith: '\powershell.exe'
    CommandLine|contains:
      - '-EncodedCommand'
      - 'DownloadString'
      - 'IEX'
  condition: selection

level: high
  

Sigma: LSASS Access by Non‑System Tool

title: LSASS Access by Non-System Tool
id: 0002-TH-LSASS-Access
status: experimental
logsource:
  product: windows
  category: process_creation

detection:
  selection:
    CommandLine|contains: 'lsass'
    Image|endswith:
      - '\procdump.exe'
      - '\rundll32.exe'
      - '\powershell.exe'
  filter_legit:
    ParentImage|endswith: '\taskmgr.exe'
  condition: selection and not filter_legit

level: high
  

Sigma: RDP Lateral Movement Spike

title: RDP Lateral Movement Spike
id: 0003-TH-RDP-Lateral
status: experimental
logsource:
  product: windows
  service: security

detection:
  selection:
    EventID: 4624
    LogonType: 10
  condition: selection

level: medium
  

✔ Final Thoughts

This Threat Hunting Queries Pack gives SOC analysts and DFIR responders a powerful set of ready‑to‑deploy detection queries across Elastic, Splunk, and Sigma. Use these queries to hunt for adversary behaviors, validate hypotheses, and strengthen your detection engineering pipeline.

Comments

Popular posts from this blog

omerta.live

AI ECOSYSTEM MAP (2026 EDITION)

AMAZON WEB SERVICES (AWS) – CLOUD PLATFORM HUB