> For the complete documentation index, see [llms.txt](https://purplebyteone.gitbook.io/index/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://purplebyteone.gitbook.io/index/notes/education/base/purple-team/thm/room/splunk/incident-handling.md).

# Incident handling

1. aim to know the attackers' tactics, techniques, and procedures
   1. The preparation phase covers the readiness of an organization against an attack
   2. The detection phase covers everything related to detecting an incident and the analysis process of the incident
      1. This phase also covers hunting for the unknown threat within the organization.
   3. Containment, Eradication, and Recovery actions needed to prevent the incident from spreading and securing the network.
      1. steps taken to avoid an attack from spreading into the network
      2. isolating the infected host
      3. clearing the network from the infection traces
      4. gaining control back from the attack
   4. Post-Incident Activity / Lessons Learnt
      1. includes identifying the loopholes in the organization's security posture
      2. improving so that the attack does not happen next time
      3. identifying weaknesses that led to the attack
      4. adding detection rules so that similar breach does not happen again
      5. training the staff if required

### Cyber Kill Chain

1. Map the attacker's activity in each phase during this Investigation \[ <https://static1.squarespace.com/static/5b636d897c932781e8002af9/t/6018dc12e670955289be56d6/1612241938544/Cyber+Kill+Chain+Report+for+APT+Group+PoisonIvy.pdf> ]
   1. Reconnaissance
   2. Weaponization
   3. Delivery
   4. Exploitation
   5. Installation
   6. Command & Control
   7. Actions on Objectives
2. log sources showing visibility into both network-centric and host-centric activities

SPLUNK \[ index=botsv1 ]

1. click on the Data summary and navigate the available tabs to get the information
   1. wineventlog
      1. It contains Windows Event logs
   2. winRegistry
      1. It contains the logs related to registry creation / modification / deletion etc.
   3. XmlWinEventLog
      1. It contains the sysmon event logs. It is a very important log source from an investigation point of view.
   4. fortigate\_utm
      1. It contains Fortinet Firewall logs
   5. iis
      1. It contains IIS web server logs
   6. Nessus:scan
      1. It contains the results from the Nessus vulnerability scanner.
   7. Suricata
      1. It contains the details of the alerts from the Suricata IDS. This log source shows which alert was triggered and what caused the alert to get triggered— a very important log source for the Investigation.
   8. stream:http
      1. It contains the network flow related to http traffic.
   9. stream: DNS
      1. It contains the network flow related to DNS traffic.
   10. stream:icmp
       1. It contains the network flow related to icmp traffic.

<details>

<summary>Reconnaissance Phase</summary>

1. Reconnaissance is an attempt to discover and collect information about a target
2. start our analysis by examining any reconnaissance attempt against the webserver `imreallynotbatman.com`
3.

```
<figure><img src="/files/C4ykIphiNr6CMEmHWRZr" alt=""><figcaption></figcaption></figure>
```

4. <mark style="color:red;">**First task is to identify the IP address attempting to perform reconnaissance activity on our web server.**</mark>

5. stream:http, which contains the http traffic logs

   1. examine the `src_ip`
   2.

   ```
   <figure><img src="/files/cjin4gspRtrGkAM1rlxY" alt=""><figcaption><p> This query will only look for the term  <code>imreallynotbatman.com</code>in the stream:http log source</p></figcaption></figure>
   ```

6. We have narrowed down the results to only show the logs from the source IP
   1\.

   ```
   <figure><img src="/files/CyMUmT8aPlaGWAoDr662" alt=""><figcaption><p>This query will show the logs from the suricata log source that are detected/generated from the source IP 40.80.248.42</p></figcaption></figure>
   ```

7. what do we need to do to validate the scanning attempt? Simple, dig further into the weblogs.
   1\.

   ```
   <figure><img src="/files/d52ZOwq1B7eGV2snObio" alt=""><figcaption></figcaption></figure>
   ```

</details>

{% hint style="info" %}
The attacker needs to exploit the vulnerability to gain access to the system/server.

* We found two IP addresses from the reconnaissance phase with sending requests to our server.
* One of the IPs `40.80.148.42` was seen attempting to scan the server with IP 192.168.250.70.
* The attacker was using the web scanner Acunetix for the scanning attempt.
  {% endhint %}

<details>

<summary>Exploitation Phase</summary>

<img src="https://2343629885-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtRrk9VAktaigFmSOtT8J%2Fuploads%2FlfckiVtuvxfaM8IMe1fb%2Fimage.png?alt=media&amp;token=da7710ce-7a7b-487c-a65e-e4d5b5028a7c" alt="This query uses the stats function to display the count of the IP addresses in the field src_ip" data-size="original">

1. index=botsv1 imreallynotbatman.com sourcetype=stream\* | stats count(src\_ip) as Requests by src\_ip | sort - Requests

&#x20;narrow down the result to show requests sent to our web server, which has the IP `192.168.250.70`

1. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70"
   1. This query will look for all the inbound traffic towards IP 192.168.250.70.

2. Check what methods were used
   1. http\_method
      1\.

      ```
      <figure><img src="/files/MnvDCTKM7lmVbEU20V25" alt=""><figcaption></figcaption></figure>
      ```

3. index=botsv1 imreallynotbatman.com sourcetype=stream:http dest\_ip="192.168.250.70" http\_method=POST
   1. src\_ip
   2. form\_data
   3. http\_user\_agent
   4. uri
   5. uri\_path
   6. http\_referrer

4. Establish CMS

5. Establish Log-on page of the CMS
   1. examining the traffic coming into this admin panel for a potential brute-force attack.

6. index=botsv1 imreallynotbatman.com sourcetype=stream:http dest\_ip="192.168.250.70" uri="/joomla/administrator/index.php"
   1. We are going to add `uri="/joomla/administrator/index.php"` in the search query to show the traffic coming into this URI.
   2. Check for form\_data
      1. contains the requests sent through the form on the admin panel page

7. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70" http\_method=POST uri="/joomla/administrator/index.php" | table \_time uri src\_ip dest\_ip form\_data
   1. &#x20;We will add this -> `| table _time uri src dest_ip form_data` to create a table
      1\.

      ```
      <figure><img src="/files/R0LeRkAmtkVYy9jfu5v0" alt=""><figcaption></figcaption></figure>
      ```

      2\.

      ```
      <figure><img src="/files/zab8SJCMBWQm4aQjUAub" alt=""><figcaption></figcaption></figure>

      1. attacker from the IP `23.22.63.114` Was trying to guess the password by brute-forcing and attempting numerous passwords.&#x20;
      2. The time elapsed between multiple events also suggests that the attacker was using an automated tool
      3.
      ```

8. Extracting Username and Passwd Fields using Regex
   1. use Regex in the search to extract only these two fields
      1. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70" http\_method=POST uri="/joomla/administrator/index.php" form\_data=*username*passwd\*\
         &#x20;\| table \_time uri src\_ip dest\_ip form\_data
         1\.

         ```
         <figure><img src="/files/TzJkJTS8sbw0dNPz5drQ" alt=""><figcaption></figcaption></figure>
         ```

      2. extract all the password values found against the field passwd in the logs
         1. `rex field=form_data "passwd=(?<creds>\w+)"`
         2. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70" http\_method=POST form\_data=*username*passwd\* | rex field=form\_data "passwd=(?\w+)" | table src\_ip creds
            1\.

            ```
            <figure><img src="/files/djNerQh6wLXSmPKdBXPz" alt=""><figcaption></figcaption></figure>
            ```

9. Investigate user agents
   1. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70" http\_method=POST form\_data=*username*passwd\* | rex field=form\_data "passwd=(?\w+)" |table \_time src\_ip uri http\_user\_agent creds
   2. Python brute-force script used
      1\.

      ```
      <figure><img src="/files/KTcJ3sOk06yK6n5ExPju" alt=""><figcaption></figcaption></figure>
      ```

</details>

{% hint style="info" %}
Once the attacker has successfully exploited the security of a system, he will try to install a backdoor or an application for persistence or to gain more control of the system.
{% endhint %}

<details>

<summary>Installation phase</summary>

1. found evidence of the webserver `iamreallynotbatman.com`
2. getting compromised via brute-force attack
3. attacker using the python script to automate getting the correct password
4. the attacker used different IP for the attack and the IP to log in to the server

What I will do:

1. Investigate any payload / malicious program uploaded to the server from any attacker's IPs
2. Check is there anything installed into the compromised server

Narrow down any http traffic coming into our server 192.168.250.70 containing the term ".exe." This query may not lead to the findings, but it's good to start from 1 extension and move ahead.

1. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70" \*.exe
   1\.

   ```
   <figure><img src="/files/9K5hHBKExDLqvgdZu4IB" alt=""><figcaption><p>find if any of these files came from the IP addresses that were found to be associated with the attack. c_ip is the client IP.</p></figcaption></figure>
   ```

2. index=botsv1 sourcetype=stream:http dest\_ip="192.168.250.70" \*.exe "part\_filename{}"="3791.exe" c\_ip="40.80.148.42"
   1\.

   ```
   <figure><img src="/files/Gz5isAAsHazKmuzP0K2B" alt=""><figcaption><p>We have 1 event. Okay but what did this file execute?</p></figcaption></figure>
   ```

3. Switch now to host-centric logs.

4. Narrow down logs to .exe file
   1\.

   ```
   <figure><img src="/files/hK7SOGI7MPBdDKD5bJSW" alt=""><figcaption><p>index=botsv1 "3791.exe"</p></figcaption></figure>
   ```

   2\. What are sysmon eventID's meanings?

   1. <https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon>
      1. #### Event ID 1: Process creation <a href="#event-id-1-process-creation" id="event-id-1-process-creation"></a>

         index=botsv1 "3791.exe" sourcetype="XmlWinEventLog" EventCode=1

         1. This query will look for the process Creation logs containing the term "3791.exe" in the logs
   2.

   ```
   <figure><img src="/files/MJscdOYjH1ygeagqoVxF" alt=""><figcaption><p>Has been executed</p></figcaption></figure>
   ```

5.

</details>

<details>

<summary>Action on Objective</summary>

start our investigation by examining the Suricata log source and the IP addresses communicating with the webserver 192.168.250.70.

index=botsv1 dest=192.168.250.70 sourcetype=suricata

Check for "source" ip.

<img src="https://2343629885-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtRrk9VAktaigFmSOtT8J%2Fuploads%2F6eMuP98Eez1tRGcmdX92%2Fimage.png?alt=media&amp;token=b035c500-ad93-4129-bce4-b5cbc0d935c9" alt="logs do not show any external IP communicating with the server. src" data-size="original">

None, see if any communication originates from the server.

index=botsv1 src=192.168.250.70 sourcetype=suricata

Check "dest\_ip"

<img src="https://2343629885-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtRrk9VAktaigFmSOtT8J%2Fuploads%2FNVE5H827mxtfUsT9OFfn%2Fimage.png?alt=media&amp;token=4a5b9a10-5b3c-4d95-9a56-89793018f7be" alt="" data-size="original">

1. Web servers do not originate the traffic
2. The browser or the client would be the source, and the server would be the destination
3. Check each ip "url"
4.

```
<figure><img src="/files/bHd44aU4pTJ71juJwS1C" alt=""><figcaption><p>Figure where jpeg came from</p></figcaption></figure>
```

5. index=botsv1 url="/poisonivy-is-coming-for-you-batman.jpeg" dest\_ip="192.168.250.70" | table \_time src dest\_ip http.hostname url
   1\.

   ```
   <figure><img src="/files/yRn0E0bKMFodd0W5Xswq" alt=""><figcaption><p>jpeg <code>poisonivy-is-coming-for-you-batman.jpeg</code> was downloaded from the attacker's host <code>prankglassinebracket.jumpingcrab.com</code> that defaced the site.</p></figcaption></figure>
   ```

   2\. or click on the .jpeg and check for "src"

   1. ![](https://2343629885-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtRrk9VAktaigFmSOtT8J%2Fuploads%2Fvod7HtKikglLB1LVuhNl%2Fimage.png?alt=media\&token=2c8d748b-f7de-4bb4-8ba5-1687b00ec1b3)

</details>

{% hint style="info" %}

* Attacker uploaded the file to the server before defacing it
* Attacker used a Dynamic DNS to resolve a malicious IP
* Examine the network-centric log sources
  * fortigate\_utm to review the firewall logs
* Objective: find the IP that the attacker decided the DNS&#x20;
  {% endhint %}

<details>

<summary>Command and Control</summary>

index=botsv1 sourcetype=fortigate\_utm"poisonivy-is-coming-for-you-batman.jpeg"

1.

```
<figure><img src="/files/65HbU6P1W5G0wqRK90dC" alt=""><figcaption></figcaption></figure>
```

2.

```
<figure><img src="/files/cN0MrSIA6fLqEd3JXUx1" alt=""><figcaption></figcaption></figure>
```

Another log source

1. index=botsv1 sourcetype=stream:http dest\_ip=23.22.63.114 "poisonivy-is-coming-for-you-batman.jpeg" src\_ip=192.168.250.70
2.

```
<figure><img src="/files/0Ka27ZFaRADWBedQC7kD" alt=""><figcaption><p>This is CNC server that has been contacted after host has been compromised.</p></figcaption></figure>
```

Check DNS log stream.

</details>

{% hint style="info" %}

* Create Malware / Malicious document to gain initial access / evade detection etc.
* Establish domains similar to the target domain to trick users.
* Create a Command and Control Server for the post-exploitation communication/activity etc.
* Found a domain `prankglassinebracket.jumpingcrab.com` associated with this attack.
* Object: find the IP address tied to the domains that may potentially be pre-staged to attack Wayne Enterprise.
  {% endhint %}

<details>

<summary>Weaponization</summary>

1. <https://www.robtex.com/>
   1\.

   ```
   <figure><img src="/files/4vykaUN4hMQNFSUiBH9J" alt=""><figcaption></figcaption></figure>
   ```

   2\.

   ```
   <figure><img src="/files/sPqoPwlO5ToLWmuMaa8j" alt=""><figcaption></figcaption></figure>
   ```

2. h[ttps://www.virustotal.com/graph/http%253A%252F%252Fprankglassinebracket.jumpingcrab.com%252F](https://www.virustotal.com/graph/http%253A%252F%252Fprankglassinebracket.jumpingcrab.com%252F)
   1\.

   ```
   <figure><img src="/files/uO9BL2gBaD6GdQKQzbo0" alt=""><figcaption><p>a lot of data there</p></figcaption></figure>
   ```

   2\.

   ```
   <figure><img src="/files/i14njZvAmZQKOCJP0LKT" alt=""><figcaption></figcaption></figure>
   ```

   3\.

   ```
   <figure><img src="/files/An5fd1n1srFm72MJBVQi" alt=""><figcaption><p>Check others below too</p></figcaption></figure>

   1. www.threatminer.org
   2. [https://whois.domaintools.com/](https://whois.domaintools.com/)
   3. ipinfo.io
   4. www.hybrid-analysis.com
   5. www.lookip.net
   6. static1.squarespace.com
   7. whatismyip.live
   8. any.run
   ```

3. <https://www.url2png.com/>

   1. po1s0n1vy.com
   2.

   ```
   <figure><img src="/files/5JvxG06iVSfNrWdM1rvy" alt=""><figcaption></figcaption></figure>
   ```

   3.

   ```
   <figure><img src="/files/8AdrzajbDkJrueGILK3c" alt=""><figcaption><p>I'll leave this hint here, so that you can practice and find the real one. Do not use writeups that are there in the wild. Try to develop skills. This is why I'm not providing solutions, only notes.</p></figcaption></figure>
   ```

   4.

   ```
   <figure><img src="/files/ekfNq7UdNft1sjbIOqDr" alt=""><figcaption></figcaption></figure>
   ```

</details>

{% hint style="info" %}
General OSINT sites:

1. Virustotal
2. ThreatMiner
3. Hybrid-Analysis
   {% endhint %}

<details>

<summary>Delivery Phase</summary>

1. <https://www.threatminer.org/host.php?q=23.22.63.114#gsc.tab=0&gsc.q=23.22.63.114&gsc.page=1>
   1. Check these
      1\.

      ```
      <figure><img src="/files/PHCRy1KS5UsAHUIxw1Tk" alt=""><figcaption></figcaption></figure>



      <figure><img src="/files/ygiiMWWgBrGkmrsrCLPz" alt=""><figcaption></figcaption></figure>



      <figure><img src="/files/0HiV1EE9U7beXInFXyPT" alt=""><figcaption></figcaption></figure>
      ```
2. <https://www.hybrid-analysis.com/sample/9709473ab351387aab9e816eff3910b9f28a7a70202e250ed46dba8f820f34a8?environmentId=100>
3.

</details>
