Machine Learning Detected a Suspicious Windows Event with a Low Malicious Probability Score
A supervised machine learning model (ProblemChild) has identified a suspicious Windows process event with low probability of it being malicious activity. Alternatively, the model's blocklist identified the event as being malicious.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2023/10/16"
3integration = ["problemchild", "endpoint"]
4maturity = "production"
5updated_date = "2024/08/21"
6
7[rule]
8author = ["Elastic"]
9description = """
10A supervised machine learning model (ProblemChild) has identified a suspicious Windows process event with low
11probability of it being malicious activity. Alternatively, the model's blocklist identified the event as being
12malicious.
13"""
14from = "now-10m"
15index = ["endgame-*", "logs-endpoint.events.process-*", "winlogbeat-*"]
16language = "eql"
17license = "Elastic License v2"
18name = "Machine Learning Detected a Suspicious Windows Event with a Low Malicious Probability Score"
19references = [
20 "https://www.elastic.co/guide/en/security/current/prebuilt-ml-jobs.html",
21 "https://docs.elastic.co/en/integrations/problemchild",
22 "https://www.elastic.co/security-labs/detecting-living-off-the-land-attacks-with-new-elastic-integration",
23]
24risk_score = 21
25rule_id = "13e908b9-7bf0-4235-abc9-b5deb500d0ad"
26setup = """## Setup
27
28The rule requires the Living off the Land (LotL) Attack Detection integration assets to be installed, as well as Windows process events collected by integrations such as Elastic Defend or Winlogbeat.
29
30### LotL Attack Detection Setup
31The LotL Attack Detection integration detects living-off-the-land activity in Windows process events.
32
33#### Prerequisite Requirements:
34- Fleet is required for LotL Attack Detection.
35- To configure Fleet Server refer to the [documentation](https://www.elastic.co/guide/en/fleet/current/fleet-server.html).
36- Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat(https://www.elastic.co/guide/en/beats/winlogbeat/current/_winlogbeat_overview.html).
37- To install Elastic Defend, refer to the [documentation](https://www.elastic.co/guide/en/security/current/install-endpoint.html).
38- To set up and run Winlogbeat, follow [this](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-installation-configuration.html) guide.
39
40#### The following steps should be executed to install assets associated with the LotL Attack Detection integration:
41- Go to the Kibana homepage. Under Management, click Integrations.
42- In the query bar, search for Living off the Land Attack Detection and select the integration to see more details about it.
43- Follow the instructions under the **Installation** section.
44- For this rule to work, complete the instructions through **Configure the ingest pipeline**.
45"""
46severity = "low"
47tags = [
48 "OS: Windows",
49 "Data Source: Elastic Endgame",
50 "Use Case: Living off the Land Attack Detection",
51 "Rule Type: ML",
52 "Rule Type: Machine Learning",
53 "Tactic: Defense Evasion",
54 "Data Source: Elastic Defend",
55]
56timestamp_override = "event.ingested"
57type = "eql"
58
59query = '''
60process where ((problemchild.prediction == 1 and problemchild.prediction_probability <= 0.98) or
61blocklist_label == 1) and not process.args : ("*C:\\WINDOWS\\temp\\nessus_*.txt*", "*C:\\WINDOWS\\temp\\nessus_*.tmp*")
62'''
63
64
65[[rule.threat]]
66framework = "MITRE ATT&CK"
67[[rule.threat.technique]]
68id = "T1036"
69name = "Masquerading"
70reference = "https://attack.mitre.org/techniques/T1036/"
71[[rule.threat.technique.subtechnique]]
72id = "T1036.004"
73name = "Masquerade Task or Service"
74reference = "https://attack.mitre.org/techniques/T1036/004/"
75
76
77
78[rule.threat.tactic]
79id = "TA0005"
80name = "Defense Evasion"
81reference = "https://attack.mitre.org/tactics/TA0005/"
References
Related rules
- Component Object Model Hijacking
- Potential Disabling of AppArmor
- Execution of File Written or Modified by Microsoft Office
- Ingress Transfer via Windows BITS
- Persistence via WMI Standard Registry Provider