INNER CODE UNIT · Python

generate_splunk_detection

magicsword-io/LOLRMM · bin/generate_detections.py:232

def generate_splunk_detection():
    """Generate a Splunk detection for RMM tools"""

    splunk_detection = {
        "name": "Generic RMM Tool Detection for Splunk",
        "id": "splunk-rmm-001",
        "description": "Detects usage of Remote Monitoring and Management (RMM) tools via network traffic",
        "author": "LOLRMM Project",
        "date": datetime.now().strftime("%Y/%m/%d"),
        "query": """| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Traffic.dest_port) as dest_port latest(user) as user from datamodel=Network_Traffic by All_Traffic.src All_Traffic.dest, All_Traffic.app 
| `drop_dm_object_name(\"All_Traffic\")` 
| `security_content_ctime(firstTime)` 
| `security_content_ctime(lastTime)` 
| lookup remote_access_software remote_appid AS app OUTPUT isutility, description as signature, comment_reference as desc, category 
| search isutility = True 
| `remote_access_software_usage_exceptions` 
| `detect_remote_access_software_usage_traffic_filter`""",
        "references": [

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…