Skip to content

Commit

Permalink
Update CAR-2021-05-008.yml
Browse files Browse the repository at this point in the history
added pseudocode
  • Loading branch information
pcmcpherson authored May 26, 2021
1 parent 9d6c902 commit 1793453
Showing 1 changed file with 11 additions and 1 deletion.
12 changes: 11 additions & 1 deletion analytics/CAR-2021-05-008.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,17 @@ coverage:
- TA0006
coverage: Moderate
implementations:
- description: ''
- name: Pseudocode – CertUtil certificate extraction
description: Pseudocode implementation of the Splunk search below
code: |-
processes = search Process:Create
certutil_downloads = filter processes where (
exe =”C:\Windows\System32\certutil.exe” AND command_line = * -exportPFX * )
output certutil_downloads
data_model: CAR native
type: Pseudocode
- name: Splunk code
description: Splunk implementation
code: '| tstats count min(_time) as firstTime values(Processes.process) as process
max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe
Processes.process = "* -exportPFX *" by Processes.parent_process Processes.process_name
Expand Down

0 comments on commit 1793453

Please sign in to comment.