Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
89 changes: 89 additions & 0 deletions data_sources/windows_event_log_defender_1116.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
name: Windows Event Log Defender 1116
id: 588d6a99-14eb-4061-aec3-55cc54d11d6b
version: 1
creation_date: '2026-08-17'
modification_date: '2026-08-17'
author: Onur Mustafa Erdogan, Splunk
description: Logs an event when a Windows Defender detects a malware or potentially unwanted software.
mitre_components:
- Application Log Content
- Host Status
- Process Creation
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: XmlWinEventLog
separator: EventCode
separator_value: '1116'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
version: 10.1.2
fields:
- _time
- Action_ID
- Action_Name
- ActivityID
- Additional_Actions_ID
- Additional_Actions_String
- Category_ID
- Category_Name
- Channel
- Computer
- Detection_ID
- Detection_Time
- Detection_User
- dvc
- dvc_nt_host
- Engine_Version
- Error_Code
- Error_Description
- event_id
- EventCode
- EventData_Xml
- EventID
- EventRecordID
- eventtype
- Execution_ID
- Execution_Name
- FWLink
- Guid
- id
- Keywords
- Level
- Name
- Opcode
- Origin_ID
- Origin_Name
- Path
- Post_Clean_Status
- Pre_Execution_Status
- Process_Name
- ProcessID
- Product_Name
- Product_Version
- RecordNumber
- Security_intelligence_Version
- severity
- Severity_ID
- severity_id
- Severity_Name
- signature_id
- Source_ID
- Source_Name
- splunk_server
- State
- Status_Code
- System_Props_Xml
- SystemTime
- tag
- Task
- TaskCategory
- ThreadID
- Threat_ID
- Threat_Name
- Type_ID
- Type_Name
- user_id
- UserID
- vendor_product
- Version
example_log: "<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Windows Defender' Guid='{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}'/><EventID>1116</EventID><Version>0</Version><Level>3</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime='2026-08-14T16:03:24.4014137Z'/><EventRecordID>1799</EventRecordID><Correlation ActivityID='{262bcfb4-42e2-4bf5-a88f-74aeb3ef10fc}'/><Execution ProcessID='380' ThreadID='8024'/><Channel>Microsoft-Windows-Windows Defender/Operational</Channel><Computer>EC2AMAZ-FKEOM7G</Computer><Security UserID='S-1-5-18'/></System><EventData><Data Name='Product Name'>Microsoft Defender Antivirus</Data><Data Name='Product Version'>4.18.26070.9</Data><Data Name='Detection ID'>{8D3B4441-6828-4720-8030-B059CF1D35D5}</Data><Data Name='Detection Time'>2026-08-14T16:03:24.393Z</Data><Data Name='Unused'></Data><Data Name='Unused2'></Data><Data Name='Threat ID'>2147519003</Data><Data Name='Threat Name'>Virus:DOS/EICAR_Test_File</Data><Data Name='Severity ID'>5</Data><Data Name='Severity Name'>Severe</Data><Data Name='Category ID'>42</Data><Data Name='Category Name'>Virus</Data><Data Name='FWLink'>https://go.microsoft.com/fwlink/?linkid=37020&amp;name=Virus:DOS/EICAR_Test_File&amp;threatid=2147519003&amp;enterprise=0</Data><Data Name='Status Code'>1</Data><Data Name='Status Description'></Data><Data Name='State'>1</Data><Data Name='Source ID'>1</Data><Data Name='Source Name'>User</Data><Data Name='Process Name'>Unknown</Data><Data Name='Detection User'>EC2AMAZ-FKEOM7G\\Administrator</Data><Data Name='Unused3'></Data><Data Name='Path'>containerfile:_\\\\.\\globalroot\\BaseNamedObjects\\Restricted\\WD_SHADOW_{AA51B3A0-AA64-4D31-8BD6-ACB4EE2000E7}\\WD_SCAN\\BERLIN; file:_\\\\.\\globalroot\\BaseNamedObjects\\Restricted\\WD_SHADOW_{AA51B3A0-AA64-4D31-8BD6-ACB4EE2000E7}\\WD_SCAN\\BERLIN-&gt;eicar.com</Data><Data Name='Origin ID'>2</Data><Data Name='Origin Name'>Network share</Data><Data Name='Execution ID'>0</Data><Data Name='Execution Name'>Unknown</Data><Data Name='Type ID'>0</Data><Data Name='Type Name'>Concrete</Data><Data Name='Pre Execution Status'>0</Data><Data Name='Action ID'>9</Data><Data Name='Action Name'>Not Applicable</Data><Data Name='Unused4'></Data><Data Name='Error Code'>0x00000000</Data><Data Name='Error Description'>The operation completed successfully. </Data><Data Name='Unused5'></Data><Data Name='Post Clean Status'>0</Data><Data Name='Additional Actions ID'>0</Data><Data Name='Additional Actions String'>No additional actions required</Data><Data Name='Remediation User'></Data><Data Name='Unused6'></Data><Data Name='Security intelligence Version'>AV: 1.457.160.0, AS: 1.457.160.0, NIS: 1.457.160.0</Data><Data Name='Engine Version'>AM: 1.1.26070.7, NIS: 1.1.26070.7</Data></EventData></Event>"
93 changes: 93 additions & 0 deletions data_sources/windows_event_log_defender_1117.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
name: Windows Event Log Defender 1117
id: c620d5f3-53d6-4697-abf5-b2c8434e7ff9
version: 1
creation_date: '2026-08-17'
modification_date: '2026-08-17'
author: Onur Mustafa Erdogan, Splunk
description: Logs an event when a Windows Defender takes an action against detected threat.
mitre_components:
- Application Log Content
- Host Status
- Process Creation
source: WinEventLog:Microsoft-Windows-Windows Defender/Operational
sourcetype: XmlWinEventLog
separator: EventCode
separator_value: '1117'
supported_TA:
- name: Splunk Add-on for Microsoft Windows
url: https://splunkbase.splunk.com/app/742
version: 10.1.2
fields:
- _time
- Action_Name
- ActivityID
- Additional_Actions_ID
- Additional_Actions_String
- Category_ID
- Category_Name
- Channel
- Computer
- Detection_ID
- Detection_Time
- Detection_User
- dvc
- dvc_nt_host
- Engine_Version
- Error_Code
- Error_Description
- event_id
- EventAction_ID
- EventCode
- EventData_Xml
- EventID
- EventRecordID
- eventtype
- Execution_ID
- Execution_Name
- FWLink
- Guid
- host
- id
- Keywords
- Level
- Name
- Opcode
- Origin_ID
- Origin_Name
- Path
- Post_Clean_Status
- Pre_Execution_Status
- Process_Name
- ProcessID
- Product_Name
- Product_Version
- RecordNumber
- Remediation_User
- Security_intelligence_Version
- severity
- Severity_ID
- severity_id
- Severity_Name
- signature_id
- source
- Source_ID
- Source_Name
- sourcetype
- splunk_server
- State
- Status_Code
- System_Props_Xml
- SystemTime
- tag
- Task
- TaskCategory
- ThreadID
- Threat_ID
- Threat_Name
- Type_ID
- Type_Name
- user_id
- UserID
- vendor_product
- Version
example_log: "<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Windows Defender' Guid='{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}'/><EventID>1117</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime='2026-08-14T16:03:29.7100826Z'/><EventRecordID>1800</EventRecordID><Correlation ActivityID='{79df46a9-3781-483e-a00d-01d3563d2405}'/><Execution ProcessID='380' ThreadID='8024'/><Channel>Microsoft-Windows-Windows Defender/Operational</Channel><Computer>EC2AMAZ-FKEOM7G</Computer><Security UserID='S-1-5-18'/></System><EventData><Data Name='Product Name'>Microsoft Defender Antivirus</Data><Data Name='Product Version'>4.18.26070.9</Data><Data Name='Detection ID'>{8D3B4441-6828-4720-8030-B059CF1D35D5}</Data><Data Name='Detection Time'>2026-08-14T16:03:24.393Z</Data><Data Name='Unused'></Data><Data Name='Unused2'></Data><Data Name='Threat ID'>2147519003</Data><Data Name='Threat Name'>Virus:DOS/EICAR_Test_File</Data><Data Name='Severity ID'>5</Data><Data Name='Severity Name'>Severe</Data><Data Name='Category ID'>42</Data><Data Name='Category Name'>Virus</Data><Data Name='FWLink'>https://go.microsoft.com/fwlink/?linkid=37020&amp;name=Virus:DOS/EICAR_Test_File&amp;threatid=2147519003&amp;enterprise=0</Data><Data Name='Status Code'>3</Data><Data Name='Status Description'></Data><Data Name='State'>2</Data><Data Name='Source ID'>1</Data><Data Name='Source Name'>User</Data><Data Name='Process Name'>Unknown</Data><Data Name='Detection User'>EC2AMAZ-FKEOM7G\\Administrator</Data><Data Name='Unused3'></Data><Data Name='Path'>containerfile:_\\\\.\\globalroot\\BaseNamedObjects\\Restricted\\WD_SHADOW_{AA51B3A0-AA64-4D31-8BD6-ACB4EE2000E7}\\WD_SCAN\\BERLIN; file:_\\\\.\\globalroot\\BaseNamedObjects\\Restricted\\WD_SHADOW_{AA51B3A0-AA64-4D31-8BD6-ACB4EE2000E7}\\WD_SCAN\\BERLIN-&gt;eicar.com</Data><Data Name='Origin ID'>2</Data><Data Name='Origin Name'>Network share</Data><Data Name='Execution ID'>0</Data><Data Name='Execution Name'>Unknown</Data><Data Name='Type ID'>0</Data><Data Name='Type Name'>Concrete</Data><Data Name='Pre Execution Status'>0</Data><Data Name='Action ID'>2</Data><Data Name='Action Name'>Quarantine</Data><Data Name='Unused4'></Data><Data Name='Error Code'>0x00000000</Data><Data Name='Error Description'>The operation completed successfully. </Data><Data Name='Unused5'></Data><Data Name='Post Clean Status'>0</Data><Data Name='Additional Actions ID'>0</Data><Data Name='Additional Actions String'>No additional actions required</Data><Data Name='Remediation User'>EC2AMAZ-FKEOM7G\\Administrator</Data><Data Name='Unused6'></Data><Data Name='Security intelligence Version'>AV: 1.457.160.0, AS: 1.457.160.0, NIS: 1.457.160.0</Data><Data Name='Engine Version'>AM: 1.1.26070.7, NIS: 1.1.26070.7</Data></EventData></Event>"
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
name: Windows Alternate Data Stream Created Over Local Share
id: e974a5c9-cbe9-4b4a-8fba-b55e7dbc8259
version: 1
creation_date: '2026-08-17'
modification_date: '2026-08-18'
author: Onur Mustafa Erdogan, Splunk
status: production
type: TTP
description: |-
The following analytic detects the creation of an NTFS alternate data stream (ADS) accessed over a local
administrative share targeting the loopback address (127.0.0.1). It leverages Windows Security Event Logs
with EventCode 5145 to identify this activity. Legitimate local processes access files directly rather than
through a local SMB share. This behavior is a hallmark of the ShieldBreak exploit, which abuses a symbolic
link swap through a loopback share to redirect a privileged, Defender-driven write into an alternate data
stream on a system-owned file, ultimately landing attacker content in C:\Windows\System32. If confirmed malicious,
this activity indicates an in-progress local privilege escalation attempt and should be investigated immediately.
data_source:
- Windows Event Log Security 5145
search: |-
`wineventlog_security`
EventCode=5145
IpAddress="127.0.0.1"
ObjectType=File
| regex RelativeTargetName="(?i)\:\w+$"
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime
by Computer IpAddress ShareName ShareLocalPath RelativeTargetName AccessMask src_user
| rename Computer as dest, IpAddress as dest_ip
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_alternate_data_stream_created_over_local_share_filter`
how_to_implement: |-
To successfully implement this search, you need to be ingesting Windows Security Event Logs with EventCode 5145 enabled. The Windows TA is also required. Enable Object Access auditing (success/failure) for File Share in group policy so that RelativeTargetName and IpAddress are populated.
known_false_positives: |-
Backup, replication, or file-sync software may occasionally write alternate data streams over administrative shares. Loopback (127.0.0.1) access to a local share is rare for legitimate software; tune by ShareName or src_user as needed for your environment.
references:
- https://www.cyderes.com/howler-cell/rogueplanet-windows-zero-day
- https://www.threatlocker.com/blog/nightmareeclipse-releases-new-poc-shieldbreak-exploits-same-weakness-as-rogueplanet
drilldown_searches:
- name: View the detection results for - "$dest$"
search: '%original_detection_search% | search dest = "$dest$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: 7d
latest_offset: "0"
finding:
title: An alternate data stream $RelativeTargetName$ was created over a loopback local share on $dest$
entity:
field: dest
type: system
score: 70
threat_objects:
- field: dest
type: system
- field: RelativeTargetName
type: file_path
- field: src_user
type: user
analytic_story:
- RoguePlanet
asset_type: Endpoint
mitre_attack_id:
- T1564.004
- T1021.002
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/emerging_threats/ShieldBreak/ads_over_local_share.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
test_type: unit
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Windows App Layer Protocol Wermgr Connect To NamedPipe
id: 2f3a4092-548b-421c-9caa-84918e1787ef
version: 10
version: 11
creation_date: '2022-10-28'
modification_date: '2026-05-13'
modification_date: '2026-08-18'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -33,6 +33,8 @@ intermediate_findings:
message: wermgr.exe process is creating or connecting to a named pipe $PipeName$ on $dest$
analytic_story:
- Qakbot
- RoguePlanet
- Windows Error Reporting Service Elevation of Privilege Vulnerability
asset_type: Endpoint
mitre_attack_id:
- T1071
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
name: Windows Defender MpClient.dll Loaded by non-Defender Process
id: 20f72601-2a92-47bc-8776-177671bbe189
version: 1
creation_date: '2026-08-17'
modification_date: '2026-08-18'
author: Onur Mustafa Erdogan, Splunk
status: production
type: TTP
description: |-
The following analytic detects mpclient.dll, the Windows Defender client API library, being loaded by a process
that is not part of the Windows Defender platform. mpclient.dll exposes the API surface used to drive on-demand
Defender scans (IOAV, MpScan). In the ShieldBreak exploit, the attacker binary loads mpclient.dll directly and
calls its scan APIs against an object-manager path in order to trigger a Defender scan against attacker-controlled
content as part of a race condition targeting Defender's placeholder-hydration behavior. If confirmed malicious,
this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
data_source:
- Sysmon EventID 7
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime max(_time) as lastTime
from datamodel=Endpoint.Processes where Processes.loaded_file="mpclient.dll" AND NOT Processes.user="* SERVICE" AND NOT Processes.user="SYSTEM" AND NOT Processes.process_path="*\MpCmdRun.exe"
AND Processes.process_path IN (
"*\\Perflogs\\*",
"*\\ProgramData\\*",
"*\\Temp\\*",
"*\\Users\\*",
"*\\Windows\\Tasks\\*")
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process
Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id
Processes.parent_process_name Processes.parent_process_path Processes.loaded_file Processes.process
Processes.process_exec Processes.process_guid Processes.process_hash Processes.process_id
Processes.process_integrity_level Processes.process_name Processes.process_path
Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_defender_mpclient_dll_loaded_by_non_defender_process_filter`
how_to_implement: |-
To successfully implement this search, you need to be ingesting logs with the driver/module loaded from your endpoints. If you are using Sysmon, configuration must explicitly include image loading events targeting mpclient.dll.
known_false_positives: |-
Third-party security products or custom AV-integration tooling that legitimately calls into the Defender client API may load mpclient.dll outside the Defender platform directories. Filter as necessary for your environment.
references:
- https://www.cyderes.com/howler-cell/rogueplanet-windows-zero-day
- https://www.threatlocker.com/blog/nightmareeclipse-releases-new-poc-shieldbreak-exploits-same-weakness-as-rogueplanet
drilldown_searches:
- name: View the detection results for - "$dest$"
search: '%original_detection_search% | search dest = "$dest$"'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$dest$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
earliest_offset: 7d
latest_offset: "0"
finding:
title: mpclient.dll was loaded by suspicious process $process_path$ on $dest$
entity:
field: dest
type: system
score: 50
threat_objects:
- field: dest
type: system
- field: process_path
type: file_path
- field: user
type: user
analytic_story:
- RoguePlanet
asset_type: Endpoint
mitre_attack_id:
- T1068
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/emerging_threats/ShieldBreak/mpclient_dll_loaded.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
Loading
Loading