
pySigma OpenSearch-Backend
Dies ist das OpenSearch-Backend für pySigma. Es stellt das Paket sigma.backends.opensearch mit zwei Backend-Klassen bereit:
OpensearchLuceneBackend - Konvertiert Sigma-Regeln in die Lucene-AbfragesyntaxOpenSearchPPLBackend - Konvertiert Sigma-Regeln in PPL-Abfragen (Piped Processing Language)Das Lucene-Backend unterstützt die folgenden Ausgabeformate:
Dieses Backend wird derzeit gepflegt von:
Da Lucene-basierte Abfragen den Elasticsearch-Lucene-Abfragen nahezu identisch sind, stammt der größte Teil des Codes für dieses Backend von pySigma-backend-elasticsearch.
Opensearch-spezifische Änderungen und Ausgabeformate werden in diesem Backend vorgenommen (z. B. Monitor-Regeln).
Das PPL-Backend (Piped Processing Language) wurde von Grund auf implementiert, um die native Abfragesprache von OpenSearch zu unterstützen. PPL bietet:
Das PPL-Backend unterstützt Sigma-Korrelationsregeln vollständig und ermöglicht die Erkennung komplexer Multi-Event-Szenarien:
sigma convert \
-t opensearch \
-p ecs_windows \
-f monitor_rule \
/data/sigma/rules/windows/process_creation/proc_creation_win_whoami_priv.yml
sigma convert \
-t opensearch-ppl \
-p ecs_windows \
/data/sigma/rules/windows/process_creation/proc_creation_win_whoami_priv.yml
from sigma.backends.opensearch import OpensearchLuceneBackend
from sigma.pipelines.sysmon import sysmon_pipeline
from sigma.pipelines.elasticsearch.windows import ecs_windows
from sigma.collection import SigmaCollection
from sigma.processing.resolver import ProcessingPipelineResolver
# Create our pipeline resolver
piperesolver = ProcessingPipelineResolver()
# Add wanted pipelines
piperesolver.add_pipeline_class(ecs_windows())
piperesolver.add_pipeline_class(sysmon_pipeline())
# Create a single sorted and prioritzed pipeline
resolved_pipeline = piperesolver.resolve(piperesolver.pipelines)
# Instantiate backend, using our resolved pipeline
# and some backend parameter
backend = OpensearchLuceneBackend(resolved_pipeline, index_names=['logs-*-*', 'beats-*'], monitor_interval=10, monitor_interval_unit="MINUTES")
rules = SigmaCollection.from_yaml("""
title: Run Whoami Showing Privileges
id: 97a80ec7-0e2f-4d05-9ef4-65760e634f6b
status: experimental
description: Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privieleges. This is often used after a privilege escalation attempt.
references:
- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/whoami
author: Florian Roth
date: 2021/05/05
modified: 2022/05/13
tags:
- attack.privilege_escalation
- attack.discovery
- attack.t1033
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: '\whoami.exe'
- OriginalFileName: 'whoami.exe'
selection_cli:
CommandLine|contains: '/priv'
condition: all of selection*
falsepositives:
- Administrative activity (rare lookups on current privileges)
level: high
""")
# Print converted rule in Lucene syntax
print("Lucene Result: \n" + "\n".join(backend.convert(rules)))
# Print converted rule ready for dsl syntax
print("DSL Result: \n" + json.dumps(backend.convert(rules, output_format="dsl_lucene")[0], indent=2))
# Generate a JSON structure to be imported as monitor rule
print("Monitor Rule Result: \n" + backend.convert(rules, output_format="monitor_rule"))
Lucene-Ergebnis:
winlog.channel:Microsoft\-Windows\-Sysmon\/Operational AND (event.code:1 AND ((process.executable:*\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND process.command_line:*\/priv*))
DSL-Ergebnis:
{
"query": {
"bool": {
"must": [
{
"query_string": {
"query": "winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND (winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND ((process.executable:*\\\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND process.command_line:*\\/priv*))))",
"analyze_wildcard": true
}
}
]
}
}
}
Monitor-Regel-Ergebnis:
{
"type": "monitor",
"name": "SIGMA - Run Whoami Showing Privileges",
"description": "Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privieleges. This is often used after a privilege escalation attempt.",
"enabled": true,
"schedule": {
"period": {
"interval": 10,
"unit": "MINUTES"
}
},
"inputs": [
{
"search": {
"indices": [
"logs-*-*",
"beats-*"
],
"query": {
"size": 1,
"query": {
"bool": {
"must": [
{
"query_string": {
"query": "winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND (winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND (winlog.channel:Microsoft\\-Windows\\-Sysmon\\/Operational AND (event.code:1 AND ((process.executable:*\\\\whoami.exe OR process.pe.original_file_name:whoami.exe) AND process.command_line:*\\/priv*))))))",
"analyze_wildcard": true
}
}
]
}
}
}
}
}
],
"tags": [
"attack-privilege_escalation",
"attack-discovery",
"attack-t1033"
],
"triggers": [
{
"name": "generated-trigger",
"severity": 2,
"condition": {
"script": {
"source": "ctx.results[0].hits.total.value > 0",
"lang": "painless"
}
},
"actions": []
}
],
"sigma_meta_data": {
"rule_id": "97a80ec7-0e2f-4d05-9ef4-65760e634f6b",
"threat": []
},
"references": [
"https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/whoami"
]
}
from sigma.backends.opensearch.opensearch_ppl import OpenSearchPPLBackend
from sigma.collection import SigmaCollection
# Instantiate PPL backend
backend = OpenSearchPPLBackend()