From 0c6a205136600da3bbacc4f4eea70ece43f8d6c5 Mon Sep 17 00:00:00 2001 From: milkmix Date: Sat, 23 Jun 2018 15:51:38 +0200 Subject: [PATCH 1/4] initial implementation supporting regkey. mutexes support waiting osquery table --- misp_modules/modules/export_mod/__init__.py | 2 +- .../modules/export_mod/osqueryexport.py | 93 +++++++++++++++++++ 2 files changed, 94 insertions(+), 1 deletion(-) create mode 100755 misp_modules/modules/export_mod/osqueryexport.py diff --git a/misp_modules/modules/export_mod/__init__.py b/misp_modules/modules/export_mod/__init__.py index 0034f5d..d2407a4 100644 --- a/misp_modules/modules/export_mod/__init__.py +++ b/misp_modules/modules/export_mod/__init__.py @@ -1 +1 @@ -__all__ = ['testexport','cef_export','liteexport','goamlexport','threat_connect_export','pdfexport','threatStream_misp_export'] +__all__ = ['testexport','cef_export','liteexport','goamlexport','threat_connect_export','pdfexport','threatStream_misp_export', 'osqueryexport'] diff --git a/misp_modules/modules/export_mod/osqueryexport.py b/misp_modules/modules/export_mod/osqueryexport.py new file mode 100755 index 0000000..715ce07 --- /dev/null +++ b/misp_modules/modules/export_mod/osqueryexport.py @@ -0,0 +1,93 @@ +""" +Export module for coverting MISP events into OSQuery query pack. +Source: https://github.com/0xmilkmix/misp-modules/blob/master/misp_modules/modules/export_mod/osqueryexport.py +""" + +import base64 +import json +import csv +import re + + +misperrors = {"error": "Error"} + +types_to_use = ['regkey', 'mutex'] + + +userConfig = { + +}; + +moduleconfig = [] + +# fixed for now, options in the future: +# event, attribute, event-collection, attribute-collection +inputSource = ['event'] + +outputFileExtension = 'conf' +responseType = 'application/txt' + + +moduleinfo = {'version': '0.1', 'author': 'Julien Bachmann, Hacknowledge', + 'description': 'OSQuery query export module', + 'module-type': ['export']} + +# test : http://misp.vm/events/view/23 +def handle_regkey(value): + rep = {'HKCU': 'HKEY_USERS\\%', 'HKLM': 'HKEY_LOCAL_MACHINE'} + rep = dict((re.escape(k), v) for k, v in rep.items()) + pattern = re.compile("|".join(rep.keys())) + value = pattern.sub(lambda m: rep[re.escape(m.group(0))], value) + return 'SELECT * FROM registry WHERE path LIKE \'%s\';' % value + +def handle_mutex(value): + return '#waiting acceptance of Scott Lundgren PR that would allow to query Kernel Objects' + +handlers = { + 'regkey' : handle_regkey, + 'mutex' : handle_mutex +} + +def handler(q=False): + if q is False: + return False + r = {'results': []} + request = json.loads(q) + output = '' + + for event in request["data"]: + for attribute in event["Attribute"]: + if attribute['type'] in types_to_use: + output = output + handlers[attribute['type']](attribute['value']) + '\n' + r = {"response":[], "data":str(base64.b64encode(bytes(output, 'utf-8')), 'utf-8')} + return r + + +def introspection(): + modulesetup = {} + try: + responseType + modulesetup['responseType'] = responseType + except NameError: + pass + try: + userConfig + modulesetup['userConfig'] = userConfig + except NameError: + pass + try: + outputFileExtension + modulesetup['outputFileExtension'] = outputFileExtension + except NameError: + pass + try: + inputSource + modulesetup['inputSource'] = inputSource + except NameError: + pass + return modulesetup + + +def version(): + moduleinfo['config'] = moduleconfig + return moduleinfo From 7c037ed090b4bb1432ecc660b6b42f7e8345ffe4 Mon Sep 17 00:00:00 2001 From: milkmix Date: Sun, 24 Jun 2018 21:09:42 +0200 Subject: [PATCH 2/4] added support for service-displayname, regkey|value --- .../modules/export_mod/osqueryexport.py | 30 +++++++++++++------ 1 file changed, 21 insertions(+), 9 deletions(-) diff --git a/misp_modules/modules/export_mod/osqueryexport.py b/misp_modules/modules/export_mod/osqueryexport.py index 715ce07..9c79d50 100755 --- a/misp_modules/modules/export_mod/osqueryexport.py +++ b/misp_modules/modules/export_mod/osqueryexport.py @@ -1,5 +1,5 @@ """ -Export module for coverting MISP events into OSQuery query pack. +Export module for coverting MISP events into OSQuery queries. Source: https://github.com/0xmilkmix/misp-modules/blob/master/misp_modules/modules/export_mod/osqueryexport.py """ @@ -11,17 +11,13 @@ import re misperrors = {"error": "Error"} -types_to_use = ['regkey', 'mutex'] - +types_to_use = ['regkey', 'regkey|value', 'mutex', 'windows-service-displayname', 'yara'] userConfig = { }; moduleconfig = [] - -# fixed for now, options in the future: -# event, attribute, event-collection, attribute-collection inputSource = ['event'] outputFileExtension = 'conf' @@ -32,7 +28,6 @@ moduleinfo = {'version': '0.1', 'author': 'Julien Bachmann, Hacknowledge', 'description': 'OSQuery query export module', 'module-type': ['export']} -# test : http://misp.vm/events/view/23 def handle_regkey(value): rep = {'HKCU': 'HKEY_USERS\\%', 'HKLM': 'HKEY_LOCAL_MACHINE'} rep = dict((re.escape(k), v) for k, v in rep.items()) @@ -40,12 +35,29 @@ def handle_regkey(value): value = pattern.sub(lambda m: rep[re.escape(m.group(0))], value) return 'SELECT * FROM registry WHERE path LIKE \'%s\';' % value +def handle_regkeyvalue(value): + key, value = value.split('|') + rep = {'HKCU': 'HKEY_USERS\\%', 'HKLM': 'HKEY_LOCAL_MACHINE'} + rep = dict((re.escape(k), v) for k, v in rep.items()) + pattern = re.compile("|".join(rep.keys())) + key = pattern.sub(lambda m: rep[re.escape(m.group(0))], key) + return 'SELECT * FROM registry WHERE path LIKE \'%s\' AND data LIKE \'%s\';' % (key, value) + def handle_mutex(value): - return '#waiting acceptance of Scott Lundgren PR that would allow to query Kernel Objects' + return 'not implemented yet' + +def handle_service(value): + return 'SELECT * FROM services WHERE display_name LIKE \'%s\' OR name like \'%s\';' % (value, value) + +def handle_yara(value): + return 'not implemented yet, not sure it\'s easily feasible w/o dropping the sig on the hosts first' handlers = { 'regkey' : handle_regkey, - 'mutex' : handle_mutex + 'regkey|value' : handle_regkeyvalue, + 'mutex' : handle_mutex, + 'windows-service-displayname' : handle_service, + 'yara' : handle_yara } def handler(q=False): From 349dd99d470bdad1c8d2a9ca758df3010a8fdd0d Mon Sep 17 00:00:00 2001 From: milkmix Date: Sun, 24 Jun 2018 21:13:56 +0200 Subject: [PATCH 3/4] added support for scheduledtasks --- misp_modules/modules/export_mod/osqueryexport.py | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/misp_modules/modules/export_mod/osqueryexport.py b/misp_modules/modules/export_mod/osqueryexport.py index 9c79d50..11c253d 100755 --- a/misp_modules/modules/export_mod/osqueryexport.py +++ b/misp_modules/modules/export_mod/osqueryexport.py @@ -11,7 +11,7 @@ import re misperrors = {"error": "Error"} -types_to_use = ['regkey', 'regkey|value', 'mutex', 'windows-service-displayname', 'yara'] +types_to_use = ['regkey', 'regkey|value', 'mutex', 'windows-service-displayname', 'windows-scheduled-task', 'yara'] userConfig = { @@ -52,11 +52,15 @@ def handle_service(value): def handle_yara(value): return 'not implemented yet, not sure it\'s easily feasible w/o dropping the sig on the hosts first' +def handle_scheduledtask(value): + return 'SELECT * FROM scheduled_tasks WHERE name LIKE \'%s\';' % value + handlers = { 'regkey' : handle_regkey, 'regkey|value' : handle_regkeyvalue, 'mutex' : handle_mutex, 'windows-service-displayname' : handle_service, + 'windows-scheduled-task' : handle_scheduledtask, 'yara' : handle_yara } From 78b4aade088a52305a160c68fa99b6ad38a4b133 Mon Sep 17 00:00:00 2001 From: milkmix Date: Wed, 3 Oct 2018 17:55:08 +0200 Subject: [PATCH 4/4] corrected typos and unused imports --- misp_modules/modules/export_mod/osqueryexport.py | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/misp_modules/modules/export_mod/osqueryexport.py b/misp_modules/modules/export_mod/osqueryexport.py index 11c253d..a1535d8 100755 --- a/misp_modules/modules/export_mod/osqueryexport.py +++ b/misp_modules/modules/export_mod/osqueryexport.py @@ -5,10 +5,8 @@ Source: https://github.com/0xmilkmix/misp-modules/blob/master/misp_modules/modul import base64 import json -import csv import re - misperrors = {"error": "Error"} types_to_use = ['regkey', 'regkey|value', 'mutex', 'windows-service-displayname', 'windows-scheduled-task', 'yara'] @@ -24,7 +22,7 @@ outputFileExtension = 'conf' responseType = 'application/txt' -moduleinfo = {'version': '0.1', 'author': 'Julien Bachmann, Hacknowledge', +moduleinfo = {'version': '1.0', 'author': 'Julien Bachmann, Hacknowledge', 'description': 'OSQuery query export module', 'module-type': ['export']}