mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
refactor(chokepoints): tighten Detection Logic prose and layout cleanup
- Condense Logic fields across 8 chokepoint pages (22 blocks total) from pseudocode-style WHERE/AND/OR constructs into plain-language 1-3 sentence descriptions matching the clickfix reference pattern. Technical specificity preserved (event IDs, access masks, paths, thresholds).
- LSASS page: align structure with clickfix template (remove redundant AttackerControls/AttackerCannotControl blocks, reformat RawLogs samples to match clickfix style with Key signal comments, add URL fields to OSINT pivots so queries are clickable)
- Layout: remove tier badges from chokepoint stage headers and raw log sample cards so badges only appear on Sigma rule examples where they add context. Switch detection logic block from white-space:pre to pre-wrap with word-break so long rules wrap instead of hiding under the horizontal scrollbar.
- Remove remaining em dashes from chokepoint layout intro copy ("Each stage is an invariant condition...", "Tools and methods that exploit this chokepoint...")
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
82321099e6
commit
6c61955380
@@ -941,7 +941,7 @@ details.emulation-wrapper[open] .emulation-lang::after { content: ''; }
|
||||
{% endif %}
|
||||
</div>
|
||||
{% else %}
|
||||
<p class="section-intro mb-5">Each stage is an invariant condition the attacker must satisfy — regardless of tool, variant, or threat actor. Detection at any stage breaks the chain.</p>
|
||||
<p class="section-intro mb-5">Each stage is an invariant condition the attacker must satisfy, regardless of tool, variant, or threat actor. Detection at any stage breaks the chain.</p>
|
||||
{% endif %}
|
||||
|
||||
<div class="chokepoints-list">
|
||||
@@ -960,7 +960,6 @@ details.emulation-wrapper[open] .emulation-lang::after { content: ''; }
|
||||
<summary class="chokepoint-header">
|
||||
<span class="cp-number">{{ forloop.index }}</span>
|
||||
<span class="cp-title">{{ stage.Stage }}</span>
|
||||
<span class="cp-maturity mat-{{ stage.DetectionTier | downcase }}">{{ stage.DetectionTier }}</span>
|
||||
<span class="cp-chevron">▶</span>
|
||||
</summary>
|
||||
<div class="chokepoint-body">
|
||||
@@ -1059,7 +1058,7 @@ details.emulation-wrapper[open] .emulation-lang::after { content: ''; }
|
||||
Variations
|
||||
<span class="section-sub">{{ cp.Variations | size }} variant{% if cp.Variations.size != 1 %}s{% endif %} tracked</span>
|
||||
</h2>
|
||||
<p class="section-intro mb-4">Tools and methods that exploit this chokepoint — the list grows; the chokepoint doesn't change.</p>
|
||||
<p class="section-intro mb-4">Tools and methods that exploit this chokepoint. The list grows. The chokepoint doesn't change.</p>
|
||||
|
||||
<div class="variations-list">
|
||||
{% for v in cp.Variations %}
|
||||
@@ -1505,13 +1504,6 @@ details.emulation-wrapper[open] .emulation-lang::after { content: ''; }
|
||||
{% if log.EventId %}<span class="log-eid">EID {{ log.EventId }}</span>{% endif %}
|
||||
<span class="log-source">{{ log.Type }}</span>
|
||||
<span class="log-desc">{{ log.Description }}</span>
|
||||
{% if log.MatchedRules %}
|
||||
<div class="rule-badges">
|
||||
{% for rule in log.MatchedRules %}
|
||||
<span class="rule-badge rb-{{ rule | downcase }}">{{ rule }}</span>
|
||||
{% endfor %}
|
||||
</div>
|
||||
{% endif %}
|
||||
<span class="log-chevron">▶</span>
|
||||
</summary>
|
||||
<div class="log-body">{{ log.Sample | xml_escape }}</div>
|
||||
|
||||
@@ -450,13 +450,7 @@ Detections:
|
||||
- Sysmon Event ID 11 (File Created / File Access)
|
||||
- Windows Security Event ID 4663 (File Access; requires Object Access auditing)
|
||||
- EDR file open telemetry (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint)
|
||||
Logic: "File Access (EID 4663 or Sysmon EID 10/11):\n TargetObject / TargetFilename:\n contains: \\Google\\Chrome\\\
|
||||
User Data\\Default\\Login Data\n OR contains: \\Google\\Chrome\\User Data\\Default\\Cookies\n OR contains: \\Google\\\
|
||||
Chrome\\User Data\\Local State\n OR contains: \\Mozilla\\Firefox\\Profiles\\\n OR contains: \\Microsoft\\Edge\\\
|
||||
User Data\\Default\\Login Data\n OR contains: \\BraveSoftware\\Brave-Browser\\User Data\\Default\\Login Data\n AccessingProcess:\
|
||||
\ NOT (chrome.exe OR msedge.exe OR brave.exe OR firefox.exe OR\n opera.exe OR vivaldi.exe OR browser\
|
||||
\ update processes)\nPurpose: Build baseline of ALL non-browser processes accessing browser credential files; identify\
|
||||
\ environments where this occurs legitimately (password managers, backup tools) vs. anomalous access.\n"
|
||||
Logic: 'Any process accessing browser credential paths (Chrome Login Data, Cookies, Local State; Firefox Profiles; Edge Login Data; Brave Login Data) where AccessingProcess is NOT the browser itself (chrome.exe, msedge.exe, brave.exe, firefox.exe, opera.exe, vivaldi.exe) or a browser update process. Run for a week to build the password-manager and backup-tool allowlist.'
|
||||
ExpectedFPRate: Medium (password managers, backup tools, some AV products)
|
||||
UseCase: 'Baseline legitimate access patterns; identify which processes routinely touch browser databases; validate EDR
|
||||
file access telemetry completeness
|
||||
@@ -471,10 +465,7 @@ Detections:
|
||||
- Sysmon Event ID 8 (CreateRemoteThread; for injection variants)
|
||||
- 'Windows API monitoring: CryptUnprotectData calls from non-browser processes'
|
||||
- EDR behavioral telemetry
|
||||
Logic: "File Access to browser credential path:\n AccessingProcess: NOT browser / NOT known password manager / NOT backup\
|
||||
\ tool\nWITHIN 60 seconds:\n API Call: CryptUnprotectData() OR NCryptUnprotectSecret()\n CallingProcess: same non-browser\
|
||||
\ process\nOR:\n Process Access (EID 10):\n TargetProcess: chrome.exe OR msedge.exe\n SourceProcess: NOT known\
|
||||
\ trusted process\n AccessRights: includes PROCESS_VM_READ (0x0010)\n (injection-based App-Bound bypass signal)\n"
|
||||
Logic: 'Non-browser, non-password-manager, non-backup process accesses a browser credential file AND within 60 seconds the same process calls CryptUnprotectData or NCryptUnprotectSecret. OR process access (EID 10) targeting chrome.exe/msedge.exe from an untrusted source with AccessRights including PROCESS_VM_READ (0x0010), the injection-based App-Bound bypass signal.'
|
||||
ExpectedFPRate: Low-Medium
|
||||
UseCase: 'Active threat hunting for infostealer activity; correlates file access with decryption API call to distinguish
|
||||
intentional credential harvesting from incidental file access by legitimate tools
|
||||
@@ -492,12 +483,7 @@ Detections:
|
||||
- Windows Security Event ID 4663 + 5156 (File Access + Windows Filtering Platform)
|
||||
- EDR network telemetry
|
||||
- DNS logs (for C2 domain resolution)
|
||||
Logic: "File Access (EID 4663 or Sysmon EID 10/11):\n TargetPath: browser credential database (Login Data OR Cookies OR\
|
||||
\ logins.json OR key4.db)\n AccessingProcess: NOT (browser process OR known password manager)\nAND within 300 seconds:\n\
|
||||
\ Network Connection (Sysmon EID 3):\n SourceProcess: same non-browser process\n DestinationIP: NOT RFC1918 (not\
|
||||
\ internal)\n DestinationPort: 80 OR 443 OR 8080 OR unusual port\nSTANDALONE HIGH-CONFIDENCE SIGNAL:\n Process accesses\
|
||||
\ Login Data AND Local State in same session\n (Local State contains App-Bound Encryption key material;\n combined access\
|
||||
\ is a strong infostealer indicator)\n"
|
||||
Logic: 'Non-browser, non-password-manager process accesses a browser credential database (Login Data, Cookies, logins.json, key4.db) AND within 300 seconds the same process makes an outbound connection to a non-RFC1918 destination on port 80, 443, 8080, or an unusual port. Standalone high-confidence signal: same process accesses Login Data AND Local State in the same session (App-Bound Encryption key combo).'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: 'SOC alerting; immediate IR escalation; the file-access + outbound-network correlation represents the full "harvest
|
||||
and exfiltrate" chain
|
||||
|
||||
@@ -520,19 +520,6 @@ Prerequisites:
|
||||
- Credential Guard (VBS) must not be active, or the attacker must compromise the isolated LSA environment (significantly harder, no known public tools)
|
||||
- Sysmon or equivalent kernel-level telemetry must be deployed for chokepoint visibility (Security EID 4656 provides partial coverage without Sysmon)
|
||||
|
||||
AttackerControls:
|
||||
- Choice of dump tool (Mimikatz, nanodump, comsvcs.dll, custom)
|
||||
- Access mask requested (0x1010, 0x1FFFFF, 0x0040, etc.)
|
||||
- API path (standard API, direct syscall, handle duplication)
|
||||
- Dump method (live parse, MiniDumpWriteDump, process forking)
|
||||
- Staging location for the dump tool
|
||||
|
||||
AttackerCannotControl:
|
||||
- Must obtain a kernel-mediated handle to lsass.exe
|
||||
- Kernel ObRegisterCallbacks fires regardless of API path
|
||||
- Sysmon EID 10 captures the handle request at kernel level
|
||||
- Credential material only exists in lsass.exe process memory
|
||||
|
||||
EvolutionTimeline:
|
||||
- Date: 2011-Q2
|
||||
Event: Mimikatz released by Benjamin Delpy
|
||||
@@ -647,14 +634,11 @@ Detections:
|
||||
Description: Baseline all non-system processes accessing lsass.exe with memory-read permissions
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
Logic: >
|
||||
Monitor ProcessAccess events where TargetImage is lsass.exe and GrantedAccess
|
||||
includes memory-read flags (0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038,
|
||||
0x1438, 0x0010). Filter only core OS processes (csrss.exe, services.exe,
|
||||
svchost.exe, lsass.exe self-access, lsaiso.exe, wininit.exe, smss.exe,
|
||||
winlogon.exe). Everything else, including AV/EDR products, WerFault,
|
||||
and Task Manager, appears in this baseline. Run for one week to establish the
|
||||
environment-specific set of legitimate LSASS accessors before tuning.
|
||||
Logic: 'Any process accessing lsass.exe with credential-dump access masks
|
||||
(0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038, 0x1438). Filter core
|
||||
OS processes only (csrss, services, svchost, lsaiso, wininit, smss,
|
||||
winlogon). Everything else, including AV/EDR and WerFault, appears here.
|
||||
Run for a week to build the environment-specific allowlist.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: >
|
||||
Detection engineers baselining LSASS access patterns in a new environment.
|
||||
@@ -667,15 +651,12 @@ Detections:
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
Logic: >
|
||||
ProcessAccess to lsass.exe with credential-dump access masks WHERE (A) CallTrace
|
||||
contains dbgcore.dll or dbghelp.dll (MiniDumpWriteDump, used by comsvcs.dll,
|
||||
ProcDump, Out-Minidump) or UNKNOWN (direct syscall / ntdll unhooking), OR (B)
|
||||
SourceImage is in a user-writable path (Temp, Downloads, AppData, ProgramData,
|
||||
Users\Public), OR (C) Process creation matches LOLBin patterns (rundll32 +
|
||||
comsvcs + MiniDump, or procdump targeting lsass). Excludes core OS processes,
|
||||
known AV/EDR paths (Program Files\Windows Defender, CrowdStrike, SentinelOne,
|
||||
Sophos, etc.), and WerFault.
|
||||
Logic: 'LSASS access with credential-dump access masks AND one of: CallTrace
|
||||
through dbgcore/dbghelp (MiniDumpWriteDump signature), UNKNOWN CallTrace
|
||||
(direct syscall), SourceImage in a user-writable path (Temp, Downloads,
|
||||
AppData, ProgramData, Users\Public), or process creation matching the
|
||||
rundll32 comsvcs MiniDump or procdump LOLBin patterns. Exclude core OS
|
||||
and known AV/EDR install paths.'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: >
|
||||
Active threat hunting for credential dumping. Periodic sweeps during incident
|
||||
@@ -687,18 +668,13 @@ Detections:
|
||||
Description: Non-standard process accessing LSASS with dump mechanism fingerprint and credential-dump access rights
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
Logic: >
|
||||
ProcessAccess to lsass.exe with credential-dump access mask (0x1FFFFF,
|
||||
0x1010, 0x1410, 0x0810, 0x1038, 0x1438) AND CallTrace shows
|
||||
MiniDumpWriteDump (dbgcore.dll, dbghelp.dll) or direct syscall (UNKNOWN)
|
||||
AND source process is outside System32 and Program Files. This triple-AND
|
||||
eliminates virtually all legitimate LSASS access; AV/EDR runs from Program
|
||||
Files with clean CallTraces. A secondary selection covers handle duplication
|
||||
(GrantedAccess 0x0040) targeting lsass from non-standard paths, catching the
|
||||
HandleKatz and nanodump duphandle evasion technique. Supplementary detections
|
||||
for comsvcs.dll MiniDump LOLBin (process_creation), SSP injection
|
||||
(image_load), and dump file artifacts (file_event) should be deployed as
|
||||
companion SIEM rules for additional coverage across event types.
|
||||
Logic: 'LSASS access with dump access mask AND CallTrace shows
|
||||
dbgcore/dbghelp or UNKNOWN AND source outside System32/Program Files.
|
||||
The triple-AND eliminates legitimate access; AV/EDR runs from Program
|
||||
Files with clean CallTraces. Secondary rule covers handle duplication
|
||||
(0x0040) from non-standard paths for HandleKatz and nanodump. Pair with
|
||||
companion rules for comsvcs MiniDump LOLBin (process_creation), SSP
|
||||
injection (image_load), and .dmp file artifacts (file_event).'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: >
|
||||
Automated SOC alerting. Direct escalation to Tier 2/IR. If this fires,
|
||||
@@ -744,43 +720,40 @@ RelatedChokepoints:
|
||||
- remote-execution-tools
|
||||
|
||||
OsintSources:
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer'
|
||||
Notes: >
|
||||
Finds malware samples that access lsass.exe during sandbox execution. Pivot
|
||||
to the behavior tab to extract GrantedAccess patterns and dump methodology
|
||||
used by each sample. Cross-reference with CallTrace values to identify
|
||||
new evasion techniques.
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+'
|
||||
Notes: >
|
||||
Finds samples containing known credential dump strings. Useful for tracking
|
||||
new Mimikatz variants, custom dump tools, and LOLBin abuse scripts that
|
||||
reference comsvcs.dll MiniDump.
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"NtOpenProcess" "lsass" language:C OR language:C++'
|
||||
Notes: >
|
||||
Finds new credential dumping tool source code. Monitor for novel evasion
|
||||
techniques: direct syscall wrappers, handle duplication implementations,
|
||||
and process forking methods that may require detection rule updates.
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#'
|
||||
Notes: >
|
||||
Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump).
|
||||
These generate dbgcore.dll in CallTrace, confirming analyst rule coverage.
|
||||
- Platform: LOLDrivers
|
||||
Query: https://www.loldrivers.io/
|
||||
Notes: >
|
||||
Database of known vulnerable kernel drivers used for BYOVD attacks. PPL
|
||||
bypass tools (PPLBlade, PPLdump) require loading a vulnerable driver before
|
||||
dumping LSASS. Cross-reference with edr-bypass-techniques chokepoint for
|
||||
driver load detection coverage.
|
||||
- Platform: ANY.RUN
|
||||
Query: 'suricata:"lsass" OR commandline:"sekurlsa" OR commandline:"comsvcs"'
|
||||
Notes: >
|
||||
Sandbox search for samples that interact with lsass.exe during execution.
|
||||
ANY.RUN provides process tree visualization showing the parent-child chain
|
||||
and GrantedAccess values, useful for building detection rule context.
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer'
|
||||
URL: https://www.virustotal.com/gui/search/behavior_processes%3A%22lsass%22%20behavior%3A%22NtOpenProcess%22%20tag%3Acred-stealer
|
||||
Notes: 'Finds malware samples that access lsass.exe during sandbox execution. Pivot to the behavior tab
|
||||
to extract GrantedAccess patterns and dump methodology used by each sample. Cross-reference with
|
||||
CallTrace values to identify new evasion techniques.'
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+'
|
||||
URL: https://www.virustotal.com/gui/search/content%3A%22sekurlsa%22%20OR%20content%3A%22MiniDumpWriteDump%22%20OR%20content%3A%22comsvcs%22%20positives%3A5%2B
|
||||
Notes: 'Finds samples containing known credential dump strings. Useful for tracking new Mimikatz
|
||||
variants, custom dump tools, and LOLBin abuse scripts that reference comsvcs.dll MiniDump.'
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"NtOpenProcess" "lsass" language:C OR language:C++'
|
||||
URL: https://github.com/search?q=%22NtOpenProcess%22+%22lsass%22+language%3AC+OR+language%3AC%2B%2B&type=code
|
||||
Notes: 'Finds new credential dumping tool source code. Monitor for novel evasion techniques: direct
|
||||
syscall wrappers, handle duplication implementations, and process forking methods that may require
|
||||
detection rule updates.'
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#'
|
||||
URL: https://github.com/search?q=%22MiniDumpWriteDump%22+%22lsass%22+OR+%22sekurlsa%22+language%3AC%23&type=code
|
||||
Notes: 'Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump). These generate
|
||||
dbgcore.dll in CallTrace, confirming analyst rule coverage.'
|
||||
- Platform: LOLDrivers
|
||||
Query: 'category:"malicious" AND (behavior:"PPL bypass" OR behavior:"LSASS access")'
|
||||
URL: https://www.loldrivers.io/
|
||||
Notes: 'Database of known vulnerable kernel drivers used for BYOVD attacks. PPL bypass tools (PPLBlade,
|
||||
PPLdump) require loading a vulnerable driver before dumping LSASS. Cross-reference with
|
||||
edr-bypass-techniques chokepoint for driver load detection coverage.'
|
||||
- Platform: ANY.RUN
|
||||
Query: 'suricata:"lsass" OR commandline:"sekurlsa" OR commandline:"comsvcs"'
|
||||
URL: https://app.any.run/submissions/?search=lsass+sekurlsa+comsvcs
|
||||
Notes: 'Sandbox search for samples that interact with lsass.exe during execution. ANY.RUN provides
|
||||
process tree visualization showing the parent-child chain and GrantedAccess values, useful for
|
||||
building detection rule context.'
|
||||
|
||||
References:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
@@ -792,73 +765,133 @@ References:
|
||||
- https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/
|
||||
|
||||
RawLogs:
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 10
|
||||
Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path'
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
- Analyst
|
||||
Sample: >
|
||||
EventID: 10 (ProcessAccess)
|
||||
UtcTime: 2025-11-14 02:31:18.442
|
||||
SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789}
|
||||
SourceProcessId: 7284
|
||||
SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
TargetProcessId: 672
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
GrantedAccess: 0x1010
|
||||
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 10
|
||||
Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass'
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
- Analyst
|
||||
Sample: >
|
||||
EventID: 10 (ProcessAccess)
|
||||
UtcTime: 2025-11-14 02:44:07.891
|
||||
SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f}
|
||||
SourceProcessId: 3412
|
||||
SourceImage: C:\Users\jsmith\Downloads\update.exe
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
TargetProcessId: 672
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
GrantedAccess: 0x1FFFFF
|
||||
CallTrace: UNKNOWN
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 10
|
||||
Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040'
|
||||
MatchedRules:
|
||||
- Analyst
|
||||
Sample: >
|
||||
EventID: 10 (ProcessAccess)
|
||||
UtcTime: 2025-11-14 03:02:55.103
|
||||
SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc}
|
||||
SourceProcessId: 5890
|
||||
SourceImage: C:\ProgramData\staging\svcloader.exe
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
TargetProcessId: 672
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
GrantedAccess: 0x0040
|
||||
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 1
|
||||
Description: 'comsvcs.dll MiniDump LOLBin: rundll32 invoking MiniDump export for LSASS dump'
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
Sample: >
|
||||
EventID: 1 (Process Create)
|
||||
UtcTime: 2025-11-14 03:15:22.667
|
||||
ProcessGUID: {a1b2c3d4-aabb-ccdd-eeff-001122334455}
|
||||
ProcessId: 8844
|
||||
Image: C:\Windows\System32\rundll32.exe
|
||||
CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
|
||||
ParentProcessGUID: {a1b2c3d4-5566-7788-99aa-bbccddeeff00}
|
||||
ParentProcessId: 4120
|
||||
ParentImage: C:\Windows\System32\cmd.exe
|
||||
ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
|
||||
- Type: Sysmon
|
||||
EventId: 10
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path'
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
- Analyst
|
||||
Sample: 'EventID: 10 (ProcessAccess)
|
||||
|
||||
UtcTime: 2025-11-14 02:31:18.442
|
||||
|
||||
SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789}
|
||||
|
||||
SourceProcessId: 7284
|
||||
|
||||
SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe
|
||||
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
|
||||
TargetProcessId: 672
|
||||
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
|
||||
GrantedAccess: 0x1010
|
||||
|
||||
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234
|
||||
|
||||
# Key signal: GrantedAccess=0x1010 (PROCESS_VM_READ | PROCESS_QUERY_INFORMATION) + TargetImage=lsass.exe
|
||||
|
||||
# SourceImage in user-writable path with full CallTrace through dbgcore.dll indicates standard MiniDumpWriteDump flow
|
||||
|
||||
'
|
||||
- Type: Sysmon
|
||||
EventId: 10
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass'
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
- Analyst
|
||||
Sample: 'EventID: 10 (ProcessAccess)
|
||||
|
||||
UtcTime: 2025-11-14 02:44:07.891
|
||||
|
||||
SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f}
|
||||
|
||||
SourceProcessId: 3412
|
||||
|
||||
SourceImage: C:\Users\jsmith\Downloads\update.exe
|
||||
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
|
||||
TargetProcessId: 672
|
||||
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
|
||||
GrantedAccess: 0x1FFFFF
|
||||
|
||||
CallTrace: UNKNOWN
|
||||
|
||||
# Key signal: CallTrace=UNKNOWN means the caller bypassed ntdll by issuing raw syscalls
|
||||
|
||||
# High GrantedAccess (0x1FFFFF = PROCESS_ALL_ACCESS) paired with opaque CallTrace is a strong direct-syscall indicator
|
||||
|
||||
'
|
||||
- Type: Sysmon
|
||||
EventId: 10
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040'
|
||||
MatchedRules:
|
||||
- Analyst
|
||||
Sample: 'EventID: 10 (ProcessAccess)
|
||||
|
||||
UtcTime: 2025-11-14 03:02:55.103
|
||||
|
||||
SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc}
|
||||
|
||||
SourceProcessId: 5890
|
||||
|
||||
SourceImage: C:\ProgramData\staging\svcloader.exe
|
||||
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
|
||||
TargetProcessId: 672
|
||||
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
|
||||
GrantedAccess: 0x0040
|
||||
|
||||
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238
|
||||
|
||||
# Key signal: GrantedAccess=0x0040 (PROCESS_DUP_HANDLE) instead of classic dump access masks
|
||||
|
||||
# Handle duplication bypasses ObRegisterCallbacks hooks that filter on PROCESS_VM_READ
|
||||
|
||||
'
|
||||
- Type: Sysmon
|
||||
EventId: 1
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: comsvcs.dll MiniDump LOLBin, rundll32 invoking MiniDump export for LSASS dump
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
Sample: 'EventID: 1 (Process Create)
|
||||
|
||||
UtcTime: 2025-11-14 03:15:22.667
|
||||
|
||||
ProcessGuid: {a1b2c3d4-aabb-ccdd-eeff-001122334455}
|
||||
|
||||
ProcessId: 8844
|
||||
|
||||
Image: C:\Windows\System32\rundll32.exe
|
||||
|
||||
CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
|
||||
|
||||
ParentProcessGuid: {a1b2c3d4-5566-7788-99aa-bbccddeeff00}
|
||||
|
||||
ParentProcessId: 4120
|
||||
|
||||
ParentImage: C:\Windows\System32\cmd.exe
|
||||
|
||||
ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
|
||||
|
||||
# Key signal: rundll32.exe loading comsvcs.dll with MiniDump export and a PID argument
|
||||
|
||||
# The PID (672) in the command line is the LSASS process ID being dumped
|
||||
|
||||
'
|
||||
|
||||
TheConstant: A process must open a kernel-mediated handle to lsass.exe and read its virtual memory to extract credential material
|
||||
|
||||
@@ -305,15 +305,7 @@ Detections:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Sysmon Event ID 11 (File Create)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
Logic: >
|
||||
Monitor process creation events for known scripting interpreter binaries
|
||||
(python.exe, python3.exe, pythonw.exe, php.exe, php-cgi.exe, node.exe, ruby.exe,
|
||||
perl.exe, lua.exe, wish.exe, tclsh.exe, Rscript.exe, dart.exe, deno.exe, bun.exe,
|
||||
AutoHotkey.exe, AutoHotkey64.exe) executing from non-standard paths. Standard
|
||||
paths to exclude: Program Files, known development tool directories, package
|
||||
manager caches. Flag any interpreter execution from C:\Temp, C:\Users\*\Downloads,
|
||||
C:\Users\*\AppData, C:\Windows\Temp, or any user-writable directory.
|
||||
Also monitor file creation events for interpreter binaries written to these paths.
|
||||
Logic: 'Any process creation or file create for known scripting interpreter binaries (python.exe, python3.exe, pythonw.exe, php.exe, php-cgi.exe, node.exe, ruby.exe, perl.exe, lua.exe, wish.exe, tclsh.exe, Rscript.exe, dart.exe, deno.exe, bun.exe, AutoHotkey.exe, AutoHotkey64.exe) from user-writable paths like C:\Temp, C:\Users\*\Downloads, C:\Users\*\AppData, or C:\Windows\Temp. Exclude Program Files, development tool directories, and package manager caches. Run to baseline the allowlist.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: >
|
||||
Baseline which interpreters exist in the environment. Identify systems where
|
||||
@@ -326,14 +318,7 @@ Detections:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Sysmon Event ID 3 (Network Connection)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
Logic: >
|
||||
Process creation where Image matches known interpreter list AND ImagePath is NOT
|
||||
in an approved development directory AND one of: (A) CommandLine contains a script
|
||||
file path (.py, .pyc, .php, .js, .rb, .pl, .lua, .tcl, .r, .ahk, .dart, .ts),
|
||||
OR (B) CommandLine contains inline execution flags (-e, -c, --eval, -exec, -r),
|
||||
OR (C) within 60 seconds the interpreter process creates an outbound network
|
||||
connection (Sysmon EID 3) to a non-RFC1918 destination. Exclude known CI/CD
|
||||
runners and developer workstations by hostname or OU.
|
||||
Logic: 'Interpreter process from outside an approved development directory AND one of: CommandLine references a script file (.py, .pyc, .php, .js, .rb, .pl, .lua, .tcl, .r, .ahk, .dart, .ts), OR CommandLine uses inline execution flags (-e, -c, --eval, -exec, -r), OR within 60 seconds the process opens an outbound connection to a non-RFC1918 destination. Exclude CI/CD runners and developer workstations by hostname or OU.'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: >
|
||||
Active threat hunting for BYOSI deployment. Correlates interpreter execution with
|
||||
@@ -348,15 +333,7 @@ Detections:
|
||||
- Sysmon Event ID 3 (Network Connection)
|
||||
- Sysmon Event ID 11 (File Create)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
Logic: >
|
||||
Correlation chain within 120-second window: (1) File creation of interpreter
|
||||
binary in user-writable directory (C:\Temp, %APPDATA%, %LOCALAPPDATA%,
|
||||
Downloads, Windows\Temp), THEN (2) Process creation of that interpreter binary
|
||||
with parent process being PowerShell, cmd.exe, wscript.exe, mshta.exe, or
|
||||
explorer.exe, AND CommandLine references a script file in a temp directory or uses
|
||||
inline execution flags, THEN (3) The interpreter process initiates an outbound
|
||||
network connection to a non-RFC1918, non-Microsoft IP address. Exclude developer
|
||||
machines, CI/CD build agents, and known package manager update processes.
|
||||
Logic: 'Within a 120-second window: interpreter binary dropped to C:\Temp, %APPDATA%, %LOCALAPPDATA%, Downloads, or Windows\Temp, THEN executed with parent powershell/cmd/wscript/mshta/explorer and CommandLine referencing a temp-dir script or inline execution flags, THEN outbound to a non-RFC1918, non-Microsoft IP. Exclude developer machines, CI/CD build agents, and package manager update processes.'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: >
|
||||
SOC alerting; direct escalation trigger for active BYOSI deployment. The three-stage
|
||||
|
||||
@@ -422,10 +422,7 @@ Detections:
|
||||
- Sysmon Event ID 6 (Driver Loaded)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Windows System Event ID 7045 (Service Installed)
|
||||
Logic: 'Event ID: 6 (Driver Loaded) Filter: Signature NOT from Microsoft OR SignatureStatus != Valid OR: Driver signed within
|
||||
last 90 days OR: Driver hash matches Microsoft Vulnerable Driver Blocklist
|
||||
|
||||
'
|
||||
Logic: 'Sysmon EID 6 driver loads where Signature is non-Microsoft, SignatureStatus is not Valid, the driver was signed within the last 90 days, or the hash matches the Microsoft Vulnerable Driver Blocklist.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: Build baseline of all drivers loaded in the environment; identify gaps in driver allowlisting; compare against
|
||||
Microsoft Vulnerable Driver Blocklist
|
||||
@@ -438,11 +435,7 @@ Detections:
|
||||
- Sysmon Event ID 10 (Process Access)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Windows System Event ID 7036 (Service State Change)
|
||||
Logic: "Driver Loaded (EID 6):\n Signature: non-Microsoft OR recently signed (<90 days) OR hash on blocklist\nWithin 5\
|
||||
\ minutes, one of:\n A. Process Terminated: target is known EDR/AV process\n (MsMpEng.exe, SophosFileScanner.exe,\
|
||||
\ CSFalconService.exe, SentinelAgent.exe)\n B. Process Created: sc.exe OR net.exe with \"stop\" targeting security service\n\
|
||||
\ C. Process Access (EID 10): source opens security process with PROCESS_TERMINATE rights\nSource: elevated process (high\
|
||||
\ integrity or SYSTEM token)\n"
|
||||
Logic: 'Driver Loaded (EID 6) non-Microsoft OR signed <90 days OR hash on blocklist, AND within 5 minutes one of: EDR/AV process terminated (MsMpEng.exe, SophosFileScanner.exe, CSFalconService.exe, SentinelAgent.exe), OR sc.exe/net.exe stop targeting a security service, OR process access (EID 10) opening a security process with PROCESS_TERMINATE. Source must be an elevated process (high integrity or SYSTEM).'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: Proactive hunt for BYOVD-based EDR killing; correlates driver load with subsequent security tool impairment
|
||||
SigmaRule: sigma-rules/edr-bypass/hunt.yml
|
||||
@@ -456,11 +449,7 @@ Detections:
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Windows Security Event ID 4624 (Logon)
|
||||
- Windows System Event ID 7036 (Service State Change)
|
||||
Logic: "Driver Loaded (EID 6):\n EITHER:\n Hash: matches Microsoft Vulnerable Driver Blocklist\n OR:\n Certificate:\
|
||||
\ issued within 14 days AND signer is unknown/unrecognized vendor\nWithin 120 seconds:\n Security process terminated\
|
||||
\ OR security service stopped (EID 7036, state: Stopped)\n Targets: MsMpEng.exe OR SophosFileScanner.exe OR CSFalconService.exe\
|
||||
\ OR\n SentinelAgent.exe OR CylanceSvc.exe\nContext:\n Source account: SYSTEM or member of local Administrators\n\
|
||||
\ After-hours (outside 08:00-18:00 local) OR source IP is non-standard admin workstation\n"
|
||||
Logic: 'Driver load (EID 6) where hash matches the Microsoft Vulnerable Driver Blocklist OR certificate was issued within 14 days by an unknown vendor, AND within 120 seconds a security process is terminated or service stopped (EID 7036) targeting MsMpEng.exe, SophosFileScanner.exe, CSFalconService.exe, SentinelAgent.exe, or CylanceSvc.exe. Source is SYSTEM or local Administrators, ideally after-hours or from a non-standard admin workstation.'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: SOC alerting; direct escalation trigger for active EDR impairment; treat as ransomware precursor
|
||||
SigmaRule: sigma-rules/edr-bypass/analyst.yml
|
||||
|
||||
@@ -194,9 +194,7 @@ Detections:
|
||||
LogSources:
|
||||
- Windows System Event ID 7036 (Service State Change)
|
||||
- Windows System Event ID 7040 (Service Start Type Change)
|
||||
Logic: 'Event ID: 7036 Service Name: Contains "sophos" OR "defender" OR "veeam" OR "backup" OR "antivirus" State: Stopped
|
||||
|
||||
'
|
||||
Logic: 'EID 7036 Stopped events where Service Name contains sophos, defender, veeam, backup, or antivirus.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: Baseline service stop frequency and patterns; identify maintenance windows vs. anomalies
|
||||
SigmaRule: sigma-rules/ransomware-service/research.yml
|
||||
@@ -206,11 +204,7 @@ Detections:
|
||||
- Windows System Event ID 7036 (Service State Change)
|
||||
- Windows System Event ID 7040 (Service Start Type Change)
|
||||
- Sysmon Event ID 1 (Process Creation for sc.exe, net.exe)
|
||||
Logic: 'Process: sc.exe OR net.exe OR powershell.exe OR taskkill.exe CommandLine: "stop" AND (service keyword in: sophos,
|
||||
defender, veeam, backup, acronis, mssql, mysql) Within 60 seconds: Same or related service: "delete" OR "disabled" via
|
||||
sc.exe OR: 3+ security/backup services stopped within 5-minute window from same process/session
|
||||
|
||||
'
|
||||
Logic: 'sc.exe, net.exe, powershell.exe, or taskkill.exe with CommandLine containing stop AND a service keyword (sophos, defender, veeam, backup, acronis, mssql, mysql), followed within 60 seconds by a delete or disable of the same service via sc.exe. Also fires when 3+ security/backup services stop within 5 minutes from the same process or session.'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: Hunt for ransomware preparation activity; identifies pre-encryption service manipulation
|
||||
SigmaRule: sigma-rules/ransomware-service/hunt.yml
|
||||
@@ -221,11 +215,7 @@ Detections:
|
||||
- Windows Security Event ID 4624 (Logon)
|
||||
- Windows System Event ID 7036 (Service State)
|
||||
- Windows System Event ID 7040/7045 (Service Config)
|
||||
Logic: "Source: Network Logon (4624, LogonType 3) OR local admin session Process: sc.exe OR net.exe OR taskkill.exe Services\
|
||||
\ stopped (5 or more within 10-minute window), targeting:\n Security: SophosFileScanner OR SAVService OR WinDefend OR\
|
||||
\ Sense OR MsMpEng\n Backup: Veeam* OR VeeamDeploymentService OR VSS OR wbengine OR *acronis*\n Database: MSSQL* OR\
|
||||
\ SQLWriter OR MySQL* OR postgresql*\nService delete: Attempted within 2 minutes of service stop Context: After-hours\
|
||||
\ activity (outside 08:00-18:00 local) OR unusual source IP\n"
|
||||
Logic: 'Network logon (4624 LogonType 3) or local admin session running sc.exe/net.exe/taskkill.exe stops 5+ services in 10 minutes targeting security (SophosFileScanner, SAVService, WinDefend, Sense, MsMpEng), backup (Veeam*, VeeamDeploymentService, VSS, wbengine, *acronis*), or database (MSSQL*, SQLWriter, MySQL*, postgresql*), with a service delete attempted within 2 minutes. Weight after-hours activity or unusual source IP.'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: SOC alerting; ransomware pre-encryption detection with minimal time to respond
|
||||
SigmaRule: sigma-rules/ransomware-service/analyst.yml
|
||||
|
||||
@@ -482,8 +482,7 @@ Detections:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Application inventory / software management telemetry
|
||||
Logic: "Process name matches known RMM tool executables:\n anydesk.exe OR screenconnect*.exe OR teamviewer*.exe OR\n ultraviewer.exe\
|
||||
\ OR rustdesk.exe OR meshagent.exe OR\n connectwisecontrol*.exe\n"
|
||||
Logic: 'Process name matches known RMM binaries: anydesk.exe, screenconnect*.exe, teamviewer*.exe, ultraviewer.exe, rustdesk.exe, meshagent.exe, connectwisecontrol*.exe.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: Asset inventory; baseline of legitimate RMM usage by IT staff
|
||||
SigmaRule: sigma-rules/renamed-rmm/research.yml
|
||||
@@ -493,11 +492,7 @@ Detections:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Sysmon Event ID 11 (File Creation)
|
||||
- Browser download telemetry
|
||||
Logic: 'File Created: *.exe Creating Process: chrome.exe OR firefox.exe OR msedge.exe OR iexplore.exe OR brave.exe File
|
||||
Path: \Downloads\ OR \Temp\ OR \AppData\Local\Temp\ Then: Process execution within 5 minutes AND: Product metadata OR
|
||||
original filename matches known RMM vendor
|
||||
|
||||
'
|
||||
Logic: '*.exe file created by a browser (chrome, firefox, msedge, iexplore, brave) in \Downloads\, \Temp\, or \AppData\Local\Temp\, then executed within 5 minutes, where product metadata or OriginalFilename matches a known RMM vendor.'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: Hunt for user-initiated RMM downloads; distinguishes IT-deployed from user-downloaded
|
||||
SigmaRule: sigma-rules/renamed-rmm/hunt.yml
|
||||
@@ -508,11 +503,7 @@ Detections:
|
||||
- Sysmon Event ID 3 (Network Connection)
|
||||
- Sysmon Event ID 11 (File Creation)
|
||||
- File metadata / version info analysis
|
||||
Logic: "File Created: *.exe via browser (see Hunt logic above) AND one of:\n - File Name contains: \"tax\" OR \"invoice\"\
|
||||
\ OR \"SSN\" OR \"SSA\" OR \"support\" OR \"verify\" OR \"secure\"\n - File Metadata: OriginalFilename = \"anydesk.exe\"\
|
||||
\ (or other RMM) but current name differs\n - File Signer: Known RMM vendor certificate on file with non-RMM name\nNetwork:\
|
||||
\ Outbound connection to RMM infrastructure within 2 minutes of execution UserContext: Standard user account (not in IT\
|
||||
\ admin group)\n"
|
||||
Logic: 'Browser-dropped *.exe (per Hunt logic) AND one of: file name contains tax, invoice, SSN, SSA, support, verify, or secure; OR OriginalFilename = anydesk.exe (or other RMM) while current name differs; OR file signed by a known RMM vendor but renamed. Fires on outbound to RMM infrastructure within 2 minutes of execution from a standard user account (not IT admin).'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: SOC alerting; campaign-themed file name detection catches targeted pretexts
|
||||
SigmaRule: sigma-rules/renamed-rmm/analyst.yml
|
||||
|
||||
@@ -240,10 +240,7 @@ Detections:
|
||||
- Windows Security Event ID 4624 (Successful Logon)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Windows System Event ID 7045 (Service Installed)
|
||||
Logic: 'Event ID: 4624 LogonType: 3 (Network) Account: Member of local Administrators or Domain Admins Within 60 seconds:
|
||||
Service creation (7045) OR process creation with elevated token
|
||||
|
||||
'
|
||||
Logic: 'Network logon (4624 LogonType 3) by a local Administrators or Domain Admins member, followed within 60 seconds by a service creation (7045) or process creation with an elevated token.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: Baseline normal admin activity; understand legitimate remote administration patterns
|
||||
SigmaRule: sigma-rules/remote-execution/research.yml
|
||||
@@ -254,10 +251,7 @@ Detections:
|
||||
- Windows Security Event ID 4624 (Logon)
|
||||
- Windows Security Event ID 4697 (Service Installed)
|
||||
- Windows System Event ID 7045 (Service Installed)
|
||||
Logic: "Network Logon (4624, LogonType 3) AND one of:\n Service Created with:\n - Name: matches random pattern (8-10\
|
||||
\ char alpha-numeric)\n - Binary Path: \\Windows\\Temp\\ OR \\Users\\Public\\ OR \\ProgramData\\\n OR Process Created\
|
||||
\ with:\n - Parent: wmiprvse.exe OR services.exe\n - Image: cmd.exe OR powershell.exe\n - Path: unusual system\
|
||||
\ paths\n"
|
||||
Logic: 'Network logon (4624 LogonType 3) AND one of: service created with a random 8-10 char alphanumeric name or binary path in \Windows\Temp\, \Users\Public\, or \ProgramData\; OR process created with parent wmiprvse.exe or services.exe spawning cmd.exe or powershell.exe from unusual paths.'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: Active hunt for lateral movement campaigns; identifies PsExec-style and WMI execution
|
||||
SigmaRule: sigma-rules/remote-execution/hunt.yml
|
||||
@@ -269,10 +263,7 @@ Detections:
|
||||
- Windows Security Event ID 4624 (Logon)
|
||||
- Windows Security Event ID 4697/7045 (Service)
|
||||
- Windows Security Event ID 5145 (Detailed File Share)
|
||||
Logic: "Network Logon (4624, LogonType 3) + IPC$ share access (5145, ShareName = IPC$) + Service creation with suspicious\
|
||||
\ characteristics:\n Name: 8-10 random alphanumeric characters\n Binary: runs from \\Windows\\Temp\\ OR \\Users\\\
|
||||
Public\\ OR command is cmd.exe/powershell.exe\nOR + Pattern: same source IP accessing 3+ hosts within 10 minutes (spray)\
|
||||
\ Source IP: internal lateral movement (RFC1918 source to RFC1918 destination)\n"
|
||||
Logic: 'Network logon (4624 LogonType 3) AND IPC$ share access (5145 ShareName=IPC$) AND service creation with a random 8-10 char name or binary in \Windows\Temp\ or \Users\Public\ or command cmd.exe/powershell.exe. Also fires on spray pattern: same source IP hitting 3+ hosts within 10 minutes, RFC1918 to RFC1918.'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: SOC alerting for active lateral movement; direct IR escalation trigger
|
||||
SigmaRule: sigma-rules/remote-execution/analyst.yml
|
||||
|
||||
@@ -353,9 +353,7 @@ Detections:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Windows Security Event ID 4688 (Process Creation with CommandLine auditing enabled)
|
||||
- Linux auditd execve syscall events
|
||||
Logic: "Process Created (EID 1 or 4688):\n ParentImage: w3wp.exe OR httpd OR apache2 OR nginx OR java OR tomcat OR php-fpm\n\
|
||||
\ ChildImage: ANY\nPurpose: Build full baseline of all child processes spawned by web server processes; identify legitimate\
|
||||
\ administration and deployment processes vs. anomalous execution\n"
|
||||
Logic: 'Any child process spawned by a web server parent (w3wp.exe, httpd, apache2, nginx, java, tomcat, php-fpm). Run to baseline legitimate administration and deployment patterns.'
|
||||
ExpectedFPRate: High
|
||||
UseCase: Baseline legitimate web server child process behavior; identify environments with routine shell spawning (misconfigured)
|
||||
vs. those with no child process spawning (well-hardened)
|
||||
@@ -367,11 +365,7 @@ Detections:
|
||||
- Sysmon Event ID 11 (File Created)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Linux auditd execve + open syscalls
|
||||
Logic: "Process Created (EID 1):\n ParentImage: w3wp.exe OR httpd OR apache2 OR nginx OR java OR php-fpm OR tomcat\n ChildImage:\n\
|
||||
\ cmd.exe OR powershell.exe OR pwsh.exe OR wscript.exe OR cscript.exe OR\n /bin/sh OR /bin/bash OR /bin/dash OR\
|
||||
\ python* OR perl OR ruby OR\n whoami.exe OR net.exe OR ipconfig.exe OR ifconfig OR id OR wget OR curl\nOR:\n File\
|
||||
\ Created (EID 11):\n Path: contains \\inetpub\\wwwroot\\ OR /var/www/ OR /srv/www/ OR /usr/share/nginx/\n Extension:\
|
||||
\ .php OR .asp OR .aspx OR .jsp OR .jspx OR .cfm OR .shtml\n CreatingProcess: NOT in approved deployment toolchain\n"
|
||||
Logic: 'Web server parent (w3wp.exe, httpd, apache2, nginx, java, php-fpm, tomcat) spawning cmd.exe, powershell.exe, pwsh.exe, wscript.exe, cscript.exe, /bin/sh, /bin/bash, /bin/dash, python*, perl, ruby, whoami.exe, net.exe, ipconfig.exe, ifconfig, id, wget, or curl. OR file create (EID 11) of .php/.asp/.aspx/.jsp/.jspx/.cfm/.shtml under \inetpub\wwwroot\, /var/www/, /srv/www/, or /usr/share/nginx/ by a process outside the approved deployment toolchain.'
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: Proactive hunt for active webshell execution and new shell file drops; distinguishes attacker activity from legitimate
|
||||
server-side scripting
|
||||
@@ -385,13 +379,7 @@ Detections:
|
||||
- Sysmon Event ID 11 (File Created)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- IIS/Apache/nginx access logs
|
||||
Logic: "File Created (EID 11) in web-accessible path:\n Extension: .php OR .asp OR .aspx OR .jsp OR .jspx\n CreatingProcess:\
|
||||
\ NOT approved CMS or deployment tool\n Time: within last 24 hours\nTHEN within 60 minutes:\n Process Created (EID 1):\n\
|
||||
\ ParentImage: w3wp.exe OR httpd OR apache2 OR java\n ChildImage: cmd.exe OR powershell.exe OR /bin/sh OR /bin/bash\n\
|
||||
\ CommandLine: contains (whoami OR net user OR net group OR ipconfig OR\n ifconfig OR id\
|
||||
\ OR wget OR curl OR certutil)\nOR (standalone — high confidence without file correlation):\n ParentImage: w3wp.exe AND\
|
||||
\ ChildImage: powershell.exe AND\n CommandLine: contains (-enc OR -EncodedCommand OR IEX OR Invoke-Expression OR\n \
|
||||
\ DownloadString OR WebClient OR FromBase64String)\n"
|
||||
Logic: 'Recent (<24h) file create of .php/.asp/.aspx/.jsp/.jspx in a web-accessible path by a process outside approved CMS/deployment tooling, followed within 60 minutes by web server parent (w3wp.exe, httpd, apache2, java) spawning cmd.exe, powershell.exe, /bin/sh, or /bin/bash with CommandLine containing whoami, net user, net group, ipconfig, ifconfig, id, wget, curl, or certutil. Standalone high-confidence: w3wp.exe spawns powershell.exe with -enc, -EncodedCommand, IEX, Invoke-Expression, DownloadString, WebClient, or FromBase64String.'
|
||||
ExpectedFPRate: Low
|
||||
UseCase: SOC alerting; immediate IR escalation; highest confidence by correlating shell file creation with subsequent command
|
||||
execution
|
||||
|
||||
Reference in New Issue
Block a user