Added detection testing service results inDisable Windows SmartScreen Protection

This commit is contained in:
root
2021-04-01 07:59:18 +00:00
parent 71139506d7
commit d35bf6fdab
@@ -6,26 +6,26 @@ author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: The following search identifies a modification of registry to disable the smartscreen protection of windows machine.
This is windows feature provide an early warning system against website that might engage in phishing attack or malware distribution.
This modification are seen in RAT malware to cover their tracks upon downloading other of its component or other payload.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry
where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_name = "Off"
by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)`
| `disable_windows_smartscreen_protection_filter`'
description: The following search identifies a modification of registry to disable
the smartscreen protection of windows machine. This is windows feature provide an
early warning system against website that might engage in phishing attack or malware
distribution. This modification are seen in RAT malware to cover their tracks upon
downloading other of its component or other payload.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmartScreenEnabled" Registry.registry_value_name
= "Off" by Registry.registry_path Registry.registry_key_name Registry.registry_value_name
Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)` | `disable_windows_smartscreen_protection_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure that this registry was included in your config
files ex. sysmon config to be monitored.
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
that this registry was included in your config files ex. sysmon config to be monitored.
known_false_positives: admin or user may choose to disable this windows features.
references:
- https://tccontre.blogspot.com/2020/01/remcos-rat-evading-windows-defender-av.html
tags:
analytic_story:
- Windows Defense Evasion Tactics
- Windows Defense Evasion Tactics
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -41,4 +41,9 @@ tags:
- Registry.user
- Registry.dest
- Registry.registry_value_nam
security_domain: endpoint
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log