mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
Adds scripts/validate_schema.py and a validate-data.yml PR gate that checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml: required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic folder consistency, and that referenced Sigma paths exist on disk. (Replaces the validate_schema.py that cp-drafter referenced but was never created.) Validator tolerates the authored conventions for Variations.Status and ExpectedFPRate (leading token + detail). Fixes surfaced by the validator/link audit: - 2 invalid Ids regenerated as real UUIDv4 (ransomware-service- manipulation, remote-execution-tools) - 4 dead reference citations repaired (Proofpoint moved URL; Trustwave via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a wrong slug -> correct article) Adds scripts/check_links.py — advisory external-link sweep (not a CI gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API endpoints and bot-blocked blogs are not mistaken for rot. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
393 lines
21 KiB
YAML
393 lines
21 KiB
YAML
Name: Ransomware Service Manipulation
|
|
Id: cfea844d-1345-4e6c-8821-3a4828f78b82
|
|
MitreIds:
|
|
- T1562.001
|
|
- T1489
|
|
Tactics:
|
|
- Defense Evasion
|
|
- Impact
|
|
Techniques:
|
|
- 'Impair Defenses: Disable or Modify Tools'
|
|
- Service Stop
|
|
DetectionPriority: CRITICAL
|
|
ThreatPrevalence: HIGH
|
|
DetectionDifficulty: LOW
|
|
Description: 'Before encrypting files, ransomware operators stop and delete security tools, backup services, and database
|
|
engines to maximize impact and prevent recovery. This is the last detectable warning before encryption begins. The chokepoint
|
|
is immutable: admin/SYSTEM privileges, service enumeration, and service stop/delete capability are always required regardless
|
|
of which ransomware family executes.
|
|
|
|
'
|
|
LastUpdated: '2026-03-07'
|
|
Author: '@iimp0ster'
|
|
Variations:
|
|
- Name: BlackBasta
|
|
FirstSeen: '2022'
|
|
Status: Legacy
|
|
SourceURL: https://reliaquest.com/blog/decline-and-legacy-of-black-basta-whats-next-ransomware-phishing/
|
|
NotesShort: Last victim posted January 2025; internal chat logs leaked February 2025; inactive by March 2025. Members migrated
|
|
to CACTUS and SafePay
|
|
Notes: Targets AV, EDR, Veeam backup, SQL databases; avg TTR 6-12 hours; last victim posted January 2025; internal Matrix
|
|
chat logs leaked February 2025; considered inactive by March 2025 after (196k messages) leaked by disgruntled member;
|
|
former members migrated to CACTUS and SafePay
|
|
VariantId: blackbasta
|
|
Command:
|
|
Invocation: "sc stop SophosService\nsc stop veeam\nsc stop MSSQLSERVER\nsc stop wbengine\nsc delete SophosService\nsc config veeam start= disabled"
|
|
Context: 'Executed via batch script or cmd.exe after gaining SYSTEM via Qakbot/Cobalt Strike. Targets AV, EDR, Veeam backup, SQL databases. Average TTR 6-12 hours from initial access.'
|
|
Artifacts:
|
|
- 'Sysmon EID 1: sc.exe with stop and security/backup service name'
|
|
- 'Sysmon EID 1: sc.exe with delete or config start= disabled'
|
|
- 'Windows System EID 7036: Multiple services stopped within 60 seconds'
|
|
- 'Windows System EID 7040: Service start type changed to disabled'
|
|
ChokepointMapping: 'SYSTEM access → sc.exe enumerates services → bulk sc stop/delete → encryption begins'
|
|
- Name: Alphv/BlackCat
|
|
FirstSeen: '2021'
|
|
Status: Legacy
|
|
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a
|
|
NotesShort: FBI-disrupted December 2023; resumed operations, attacked Change Healthcare February 2024; exit-scammed affiliates
|
|
March 2024 after $22M ransom
|
|
Notes: Targets Sophos, Defender, VSS, SQL; cross-platform (Windows and Linux/ESXi); FBI disruption December 2023; exited
|
|
via scam March 2024 after $22M Change Healthcare ransom. Leadership withheld affiliate commissions and shut down infrastructure
|
|
VariantId: alphv-blackcat
|
|
Command:
|
|
Invocation: "# Windows Rust binary with embedded service list:\nnet stop \"Sophos Agent\" /y\nnet stop \"vss\" /y\nnet stop \"MSSQL$SQLEXPRESS\" /y\nwmic service where \"name like '%backup%'\" call stopservice"
|
|
Context: 'Cross-platform (Windows Rust, Linux C). Windows variant embeds a service kill list. Also uses vssadmin to delete shadow copies. FBI disruption Dec 2023, exit scam March 2024.'
|
|
Artifacts:
|
|
- 'Sysmon EID 1: net.exe or net1.exe with stop and service name'
|
|
- 'Sysmon EID 1: wmic.exe with service and stopservice'
|
|
- 'Sysmon EID 1: vssadmin.exe with delete shadows'
|
|
- 'Windows System EID 7036: Bulk service stops'
|
|
ChokepointMapping: 'SYSTEM → embedded kill list → net stop / wmic stopservice → vssadmin delete shadows → encryption'
|
|
- Name: Akira
|
|
FirstSeen: '2023'
|
|
Status: Active
|
|
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a
|
|
NotesShort: Prioritizes Defender and backup agents; targets VPN appliances for initial access
|
|
Notes: Prioritizes Defender and backup agents; targets VPN appliances for initial access
|
|
VariantId: akira
|
|
Command:
|
|
Invocation: "powershell -Command \"Get-Service -Name *sophos*, *veeam*, *sql*, *backup* | Stop-Service -Force\"\nsc config WinDefend start= disabled\nnet stop WinDefend /y"
|
|
Context: 'Prioritizes Defender and backup agents. Initial access via VPN appliances (Cisco, Fortinet). Uses PowerShell for service manipulation alongside sc.exe.'
|
|
Artifacts:
|
|
- 'Sysmon EID 1: powershell.exe with Stop-Service -Force and wildcard service names'
|
|
- 'Sysmon EID 1: sc.exe with config WinDefend start= disabled'
|
|
- 'Windows System EID 7036: Defender + backup services stopped'
|
|
ChokepointMapping: 'Admin via VPN compromise → PowerShell Get-Service enumeration → Stop-Service -Force → sc config disable'
|
|
- Name: Qilin
|
|
FirstSeen: '2022'
|
|
Status: Active
|
|
SourceURL: https://socradar.io/blog/dark-web-profile-qilin-agenda-ransomware/
|
|
NotesShort: Rebranded from Agenda; surged with NHS/Synnovis attack June 2024
|
|
Notes: Originally tracked as Agenda (Golang); rebranded to Qilin and rewrote in Rust in 2022; fully operational RaaS by
|
|
February 2023; targets EDR, Veeam, databases; VMware ESXi variant active; surged to prominence with NHS/Synnovis attack
|
|
June 2024
|
|
VariantId: qilin
|
|
Command:
|
|
Invocation: "# Rust binary - service manipulation via Windows API, not sc.exe:\nqilin.exe --kill-services --paths \\\\DC\\SYSVOL\\domain\\scripts\\\n# ESXi variant:\nesxcli vm process list\nesxcli vm process kill --type=force --world-id=<id>"
|
|
Context: 'Rewritten in Rust (2022). Uses Windows API directly for service manipulation, reducing sc.exe command-line artifacts. ESXi variant kills VM processes before encrypting VMDK files.'
|
|
Artifacts:
|
|
- 'Windows System EID 7036: EDR/backup services stopped without sc.exe CLI'
|
|
- 'Sysmon EID 1: Qilin binary execution with --kill-services'
|
|
- 'ESXi: esxcli process kill events in hostd.log'
|
|
ChokepointMapping: 'SYSTEM → Windows API service stop (no sc.exe) → service state changes (EID 7036) → encryption'
|
|
- Name: LockBit 3.0
|
|
FirstSeen: '2022'
|
|
Status: Declining
|
|
SourceURL: https://www.trendmicro.com/en_us/research/24/d/operation-cronos-aftermath.html
|
|
NotesShort: Operation Cronos seized 28 servers and 1,000+ decryption keys; significantly disrupted
|
|
Notes: Comprehensive kill list (50+ services); Group Policy abuse for domain-wide deployment; Operation Cronos (February
|
|
2024) seized 28 servers, source code, and 1000+ decryption keys. Significantly reduced operational capacity
|
|
VariantId: lockbit-3-0
|
|
Command:
|
|
Invocation: "# Domain-wide via Group Policy scheduled task:\nschtasks /create /tn \"Windows Update\" /tr \"C:\\windows\\temp\\lockbit.exe\" /sc once /st 00:00 /ru SYSTEM\n# Kill list (50+ services):\nsc stop SophosFileScanner\nsc stop CrowdStrike\nsc stop SentinelAgent\nsc stop veeam\nsc stop MSSQLSERVER\nsc stop wbengine\nsc stop VSS\n# ... 40+ more services\nvssadmin delete shadows /all /quiet\nbcdedit /set {default} recoveryenabled No"
|
|
Context: 'Most comprehensive kill list (50+ services). Uses Group Policy for domain-wide deployment. Disables Windows recovery and deletes shadow copies. Operation Cronos (Feb 2024) seized infrastructure.'
|
|
Artifacts:
|
|
- 'Sysmon EID 1: 50+ sc.exe stop commands in rapid succession'
|
|
- 'Sysmon EID 1: vssadmin.exe delete shadows /all /quiet'
|
|
- 'Sysmon EID 1: bcdedit.exe /set recoveryenabled No'
|
|
- 'Sysmon EID 1: schtasks.exe /create with SYSTEM context'
|
|
- 'Windows System EID 7036: 50+ services stopped in under 5 minutes'
|
|
- 'Security EID 4698: Scheduled task created across multiple hosts'
|
|
ChokepointMapping: 'Domain admin → GPO scheduled task → 50+ sc stop commands → vssadmin + bcdedit → domain-wide encryption'
|
|
Prerequisites:
|
|
- Admin or SYSTEM privileges already established on target system
|
|
- Target security, backup, and database services are running (cannot stop what is not running)
|
|
Chokepoints:
|
|
- Stage: Service Enumeration
|
|
Input: Attacker has SYSTEM privileges on the target system
|
|
Invariant: Actor enumerates running services to build the kill list via sc query, Get-Service, wmic, or equivalent
|
|
Observable: 'Sysmon EID 1 showing sc.exe query, wmic service get, or Get-Service commands. Multiple service
|
|
enumeration commands in rapid succession from the same process or user context.'
|
|
WhyCantBypass: Ransomware cannot stop what it cannot find. Service enumeration precedes every observed kill sequence across
|
|
all documented families. sc.exe stop and delete require Admin or SYSTEM privileges, so no privilege escalation means immediate
|
|
failure before enumeration can complete
|
|
LogSources:
|
|
- Sysmon Event ID 1 (sc.exe query / wmic service get / Get-Service)
|
|
- Windows Security Event ID 4688 (Process Creation)
|
|
DetectionTier: Research
|
|
SigmaRef: sigma-rules/ransomware-service/research.yml
|
|
- Stage: Bulk Service Stop
|
|
Input: Service kill list has been built via enumeration
|
|
Invariant: Security, backup, and database services are stopped in rapid succession via sc.exe, net stop, taskkill, or WMI
|
|
StopService. Multiple services within a short window
|
|
Observable: 'Windows System EID 7036 showing multiple security/backup services transitioning to "stopped" state
|
|
within 60 seconds. Sysmon EID 1 showing repeated sc stop or net stop commands.'
|
|
WhyCantBypass: Files locked by running services cannot be encrypted. Stop must precede encryption in every observed ransomware
|
|
family without exception
|
|
LogSources:
|
|
- Windows System Event ID 7036 (Service State Change - stopped)
|
|
- Windows System Event ID 7040 (Service Start Type Changed - disabled)
|
|
- Sysmon Event ID 1 (sc.exe / net.exe / taskkill.exe process creation)
|
|
DetectionTier: Hunt
|
|
SigmaRef: sigma-rules/ransomware-service/hunt.yml
|
|
BypassNote: Purpose-built EDR killers (BYOVD drivers, EDRKillShifter) bypass service-stop detection by killing the EDR process
|
|
at kernel level. Monitor Sysmon EID 6 for suspicious driver loads immediately before bulk service termination
|
|
- Stage: Service Deletion
|
|
Input: Target services have been stopped
|
|
Invariant: Stopped services are deleted or permanently disabled to prevent automatic restart during the encryption phase
|
|
Observable: 'Sysmon EID 1 showing sc.exe delete or sc.exe config start= disabled commands targeting security
|
|
and backup services. Registry changes under HKLM\SYSTEM\CurrentControlSet\Services\ confirming service deletion.'
|
|
WhyCantBypass: Without deletion, Windows service recovery policies restart stopped services and interfere with encryption.
|
|
Deletion is confirmed across all major documented families
|
|
LogSources:
|
|
- Sysmon Event ID 1 (sc.exe delete / sc.exe config start= disabled)
|
|
- Sysmon Event ID 12/13 (Registry key deletion under Services hive)
|
|
DetectionTier: Analyst
|
|
SigmaRef: sigma-rules/ransomware-service/analyst.yml
|
|
EvolutionTimeline:
|
|
- Date: 2021-Q2
|
|
Event: Database services added to kill lists
|
|
Change: SQL Server, MySQL, and PostgreSQL services added to kill lists to release file locks before encryption.
|
|
DetectionImpact: Database service monitoring becomes a required detection component
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2022-Q3
|
|
Event: Multi-vendor EDR evasion; kill lists expand to 50+ security products
|
|
Change: Kill lists expand to 50+ security products covering all major AV/EDR; threshold-based detection required.
|
|
DetectionImpact: Cannot rely on specific product name matches; threshold-based detection required
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2023-Q4
|
|
Event: Backup services prioritized ahead of AV/EDR in kill sequence
|
|
Change: Veeam, Acronis, and Windows Backup targeted before AV/EDR; backup service monitoring becomes highest-priority signal.
|
|
DetectionImpact: Backup service monitoring becomes highest priority signal
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2024-Q2
|
|
Event: ESXi hypervisor service targeting increases
|
|
Change: VM-based service disruption targets vmware-hostd, vpxa, vsanmgmtd; ESXi-specific logging required.
|
|
DetectionImpact: ESXi-specific logging (vSphere/vCenter) required; endpoint detection insufficient
|
|
Variants: []
|
|
EventType: event
|
|
- Date: 2024-Q3
|
|
Event: Purpose-built EDR killer tooling becomes standard
|
|
Change: RansomHub ships EDRKillShifter; DeadLock embeds a weaponized Baidu driver; ~25% of 2024 ransomware attacks incorporated
|
|
purpose-built EDR disablement.
|
|
DetectionImpact: Cannot rely on known-bad driver hashes alone; monitor for driver load events (Sysmon EID 6) of unsigned
|
|
or recently signed drivers immediately before service manipulation
|
|
Variants: []
|
|
EventType: event
|
|
Detections:
|
|
- Level: Research
|
|
Description: Identify security or backup service state changes (stopped)
|
|
LogSources:
|
|
- Windows System Event ID 7036 (Service State Change)
|
|
- Windows System Event ID 7040 (Service Start Type Change)
|
|
Logic: 'EID 7036 Stopped events where Service Name contains sophos, defender, veeam, backup, or antivirus.'
|
|
ExpectedFPRate: High
|
|
UseCase: Baseline service stop frequency and patterns; identify maintenance windows vs. anomalies
|
|
SigmaRule: sigma-rules/ransomware-service/research.yml
|
|
- Level: Hunt
|
|
Description: Service stop + delete combination for security or backup services in rapid succession
|
|
LogSources:
|
|
- Windows System Event ID 7036 (Service State Change)
|
|
- Windows System Event ID 7040 (Service Start Type Change)
|
|
- Sysmon Event ID 1 (Process Creation for sc.exe, net.exe)
|
|
Logic: 'sc.exe, net.exe, powershell.exe, or taskkill.exe with CommandLine containing stop AND a service keyword (sophos, defender, veeam, backup, acronis, mssql, mysql), followed within 60 seconds by a delete or disable of the same service via sc.exe. Also fires when 3+ security/backup services stop within 5 minutes from the same process or session.'
|
|
ExpectedFPRate: Medium
|
|
UseCase: Hunt for ransomware preparation activity; identifies pre-encryption service manipulation
|
|
SigmaRule: sigma-rules/ransomware-service/hunt.yml
|
|
- Level: Analyst
|
|
Description: Network logon + bulk service termination targeting specific security/backup services within a tight window
|
|
LogSources:
|
|
- Sysmon Event ID 1 (Process Creation)
|
|
- Windows Security Event ID 4624 (Logon)
|
|
- Windows System Event ID 7036 (Service State)
|
|
- Windows System Event ID 7040/7045 (Service Config)
|
|
Logic: 'Network logon (4624 LogonType 3) or local admin session running sc.exe/net.exe/taskkill.exe stops 5+ services in 10 minutes targeting security (SophosFileScanner, SAVService, WinDefend, Sense, MsMpEng), backup (Veeam*, VeeamDeploymentService, VSS, wbengine, *acronis*), or database (MSSQL*, SQLWriter, MySQL*, postgresql*), with a service delete attempted within 2 minutes. Weight after-hours activity or unusual source IP.'
|
|
ExpectedFPRate: Low
|
|
UseCase: SOC alerting; ransomware pre-encryption detection with minimal time to respond
|
|
SigmaRule: sigma-rules/ransomware-service/analyst.yml
|
|
Intel:
|
|
- Name: Kaspersky Common TTPs of Modern Ransomware
|
|
Tier: primary
|
|
URL: https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
|
|
Description: Comprehensive analysis of service kill lists across major ransomware families
|
|
- Name: 'MITRE ATT&CK - T1562.001 Impair Defenses: Disable or Modify Tools'
|
|
Tier: primary
|
|
URL: https://attack.mitre.org/techniques/T1562/001/
|
|
Description: Technique definition, procedure examples, and detection guidance for disabling or modifying security tools
|
|
- Name: MITRE ATT&CK - T1489 Service Stop
|
|
Tier: primary
|
|
URL: https://attack.mitre.org/techniques/T1489/
|
|
Description: Technique definition, procedure examples, and detection guidance for stopping services to impair system recovery
|
|
RelatedChokepoints:
|
|
- remote-execution-tools
|
|
- clickfix-techniques
|
|
OsintSources:
|
|
- Platform: VirusTotal Intelligence
|
|
Query: behavior_processes:"sc.exe" tag:ransomware
|
|
URL: https://www.virustotal.com/gui/search/behavior_processes%3A%22sc.exe%22%20tag%3Aransomware
|
|
Notes: Requires VT Intelligence subscription; pivot to the behavior tab to extract the full service kill list for each ransomware
|
|
family and feed service names into the analyst Sigma rule.
|
|
- Platform: GitHub Code Search
|
|
Query: '"net stop" "sc delete" ransomware path:*.ps1 OR path:*.bat OR path:*.txt'
|
|
URL: https://github.com/search?q=%22net+stop%22+%22sc+delete%22+ransomware&type=code
|
|
Notes: Finds researcher-published kill lists extracted from decompiled ransomware samples; update the analyst rule's service
|
|
name list whenever new families are documented.
|
|
- Platform: ANY.RUN Public Feed
|
|
URL: https://app.any.run/submissions#status=public&tag=ransomware
|
|
Notes: Public ransomware task feed; filter to recent submissions and inspect process trees to see sc.exe and net.exe child
|
|
process chains without a local sandbox.
|
|
- Platform: Ransomware.live
|
|
URL: https://www.ransomware.live
|
|
Notes: Real-time ransomware group activity tracker; use to identify currently active families and prioritize hunting for
|
|
their service kill lists.
|
|
KnownBypasses:
|
|
- Bypass: Tamper protection enabled on EDR (requires kernel-level access to disable)
|
|
Mitigation: Enable tamper protection on all EDR products; require a signed kernel driver to disable it.
|
|
- Bypass: Renaming service before stopping (evades name-based filters)
|
|
Mitigation: Allowlist by service binary path rather than service name; alert on service config changes before stop.
|
|
- Bypass: Process termination (taskkill /F) instead of service stop
|
|
Mitigation: Enable Protected Process Light (PPL) for EDR processes.
|
|
- Bypass: WMI or PowerShell-based service stop (evades sc.exe/net.exe process-creation detections)
|
|
Mitigation: Monitor WMI activity broadly and restrict WMI remoting via host firewall where not operationally required.
|
|
- Bypass: Purpose-built EDR killer tools (EDRKillShifter, weaponized drivers bundled with ransomware)
|
|
Mitigation: Enable HVCI and the Microsoft Vulnerable Driver Blocklist; enforce driver signing policy.
|
|
RawLogs:
|
|
- Type: Sysmon
|
|
EventId: 1
|
|
Source: Microsoft-Windows-Sysmon/Operational
|
|
Description: sc.exe used to stop a backup service - first service in rapid bulk-stop sequence
|
|
MatchedRules:
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 1 (Process Create)
|
|
|
|
UtcTime: 2024-06-17 22:11:03.447
|
|
|
|
ProcessId: 5532
|
|
|
|
Image: C:\Windows\System32\sc.exe
|
|
|
|
CommandLine: sc stop VeeamBackupSvc
|
|
|
|
ParentImage: C:\Windows\System32\cmd.exe
|
|
|
|
'
|
|
- Type: Windows Event Log
|
|
EventId: 7036
|
|
Source: Service Control Manager
|
|
Description: Veeam backup service stopped as part of ransomware pre-encryption service kill
|
|
MatchedRules:
|
|
- Research
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 7036 (The service entered the stopped state)
|
|
|
|
TimeCreated: 2024-06-17T22:11:03.8834120Z
|
|
|
|
Channel: System
|
|
|
|
param1: Veeam Backup Service
|
|
|
|
param2: stopped
|
|
|
|
'
|
|
- Type: Sysmon
|
|
EventId: 1
|
|
Source: Microsoft-Windows-Sysmon/Operational
|
|
Description: sc.exe disables service to prevent automatic restart
|
|
MatchedRules:
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 1 (Process Create)
|
|
|
|
UtcTime: 2024-06-17 22:11:04.112
|
|
|
|
ProcessId: 5540
|
|
|
|
Image: C:\Windows\System32\sc.exe
|
|
|
|
CommandLine: sc config VeeamBackupSvc start= disabled
|
|
|
|
ParentImage: C:\Windows\System32\cmd.exe
|
|
|
|
'
|
|
- Type: Windows Event Log
|
|
EventId: 7040
|
|
Source: Service Control Manager
|
|
Description: Backup service start type changed to disabled - prevents auto-restart
|
|
MatchedRules:
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 7040 (The start type of the service was changed)
|
|
|
|
TimeCreated: 2024-06-17T22:11:04.2201830Z
|
|
|
|
Channel: System
|
|
|
|
param1: Veeam Backup Service
|
|
|
|
param2: disabled
|
|
|
|
'
|
|
- Type: Sysmon
|
|
EventId: 1
|
|
Source: Microsoft-Windows-Sysmon/Operational
|
|
Description: Service deleted to remove backup infrastructure entirely
|
|
MatchedRules:
|
|
- Hunt
|
|
- Analyst
|
|
Sample: 'EventID: 1 (Process Create)
|
|
|
|
UtcTime: 2024-06-17 22:11:07.883
|
|
|
|
ProcessId: 5548
|
|
|
|
Image: C:\Windows\System32\sc.exe
|
|
|
|
CommandLine: sc delete VeeamBackupSvc
|
|
|
|
ParentImage: C:\Windows\System32\cmd.exe
|
|
|
|
'
|
|
EmulationScript:
|
|
File: emulation/ransomware-service-manipulation/emulate.ps1
|
|
Language: powershell
|
|
Description: Simulates bulk service stop, disable, and delete pattern used by ransomware pre-encryption
|
|
SafetyNotes: Requires Administrator. Creates dummy test services. Optionally targets VSS. Lab VM only.
|
|
AtomicRef: T1562.001
|
|
TheConstant: SYSTEM-level process → service enumeration → bulk service stop/delete → encryption begins
|
|
PreventionSummary: >
|
|
Ransomware's pre-encryption kill phase relies on a small set of well-known binaries to stop
|
|
security and backup services. Application control can block or alert on these tools before
|
|
they succeed, buying defenders critical response time before encryption begins.
|
|
PreventionOpportunities:
|
|
- Category: Endpoint · Application Control
|
|
Control: Restrict which processes may invoke service stop/delete commands
|
|
Impact: Blocks or delays the pre-encryption kill phase; even a short delay gives defenders
|
|
time to intervene before files are encrypted.
|
|
MagicSwordFit: MagicSword's Spawn Control rules restrict which parent processes can invoke
|
|
service-manipulation binaries (sc.exe, net.exe, taskkill.exe), blocking ransomware kill
|
|
scripts without affecting legitimate IT workflows.
|
|
MagicSwordTag: lolbas
|
|
- Category: Endpoint
|
|
Control: Enable Tamper Protection on your EDR/AV and all security tools
|
|
Impact: Prevents security services from being stopped even by processes running as SYSTEM,
|
|
preserving visibility at the point when it matters most.
|
|
- Category: Backup
|
|
Control: Enforce immutable, offline-separated backups and restrict vssadmin access
|
|
Impact: Preserves recovery options even if ransomware completes its kill list; removes the
|
|
business leverage that makes ransom payment attractive.
|