diff --git a/queries/Public_IP_Successfully_Authenticated_Following_Brute_Force_Activity.yml b/queries/Public_IP_Successfully_Authenticated_Following_Brute_Force_Activity.yml new file mode 100644 index 0000000..58ded39 --- /dev/null +++ b/queries/Public_IP_Successfully_Authenticated_Following_Brute_Force_Activity.yml @@ -0,0 +1,61 @@ +# --- Query Metadata --- +# Human-readable name for the query. Will be displayed as the title. +name: "Public IP Successfully Authenticated Following Brute Force Activity" + +# MITRE ATT&CK technique IDs +mitre_ids: + - "T1110.001" + +# Description of what the query does and its purpose. +description: "Detects account access events where CrowdStrike identified a successful login after brute force attempts originating from an internet-routable IP address." + +# The author or team that created the query. +author: "Kundan Kumar" + +# The required log sources to run this query successfully in Next-Gen SIEM. +log_sources: + - Endpoint + +# Tags for filtering and categorization. +tags: + - Detection + +cs_required_modules: + - Insight + +# --- Query Content --- +# The actual CrowdStrike Query Language (CQL) code. +cql: | + #Vendor ="crowdstrike" + |"#event_simpleName" ="RemoteBruteForceDetectInfo" + | DetectDescription=~/^A public IP successfully brute forced an account on this system/ + |table([@timestamp,ComputerName,user.name,RemoteIP]) + +# Explanation of the query. Uses markdown for formatting on the webpage. +explanation: | + 1. Filter CrowdStrike events + + #Vendor ="crowdstrike" + + + Restricts the search to logs ingested from CrowdStrike. + + 2. Filter for brute-force detection events + + "#event_simpleName" ="RemoteBruteForceDetectInfo" + + Returns only events generated by CrowdStrike's brute-force detection logic. These events indicate that CrowdStrike identified suspicious authentication activity consistent with a brute-force attack. + + 3. Filter for successful brute-force compromises + + DetectDescription=~/^A public IP successfully brute forced an account on this system/ + + Uses a regular expression to match detection descriptions beginning with: + + A public IP successfully brute forced an account on this system + + This is the most important filter because it narrows the results to cases where: + + The source was a publicly routable IP address. + The brute-force attack was successful. + An account on the endpoint was successfully authenticated after repeated login attempts.