mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
65 lines
2.2 KiB
YAML
65 lines
2.2 KiB
YAML
name: Delete ShadowCopy With PowerShell
|
|
id: 5ee2bcd0-b2ff-11eb-bb34-acde48001122
|
|
version: 1
|
|
date: '2021-05-12'
|
|
author: Teoderick Contreras, Splunk
|
|
type: TTP
|
|
datamodel:
|
|
- Endpoint
|
|
description: This following analytic detects PowerShell command to delete shadow copy
|
|
using the WMIC PowerShell module. This technique was seen used by a recent adversary
|
|
to deploy DarkSide Ransomware where it executed a child process of PowerShell to
|
|
execute a hex encoded command to delete shadow copy. This hex encoded command was
|
|
able to be decrypted by PowerShell log.
|
|
search: '`powershell` EventCode=4104 Message= "*ShadowCopy*" (Message = "*Delete*"
|
|
OR Message = "*Remove*") | stats count min(_time) as firstTime max(_time) as lastTime
|
|
by EventCode Message ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
|
| `delete_shadowcopy_with_powershell_filter`'
|
|
how_to_implement: To successfully implement this search, you need to be ingesting
|
|
logs with the powershell logs from your endpoints. make sure you enable needed
|
|
registry to monitor this event.
|
|
known_false_positives: unknown
|
|
references:
|
|
- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html
|
|
- https://searchwindowsserver.techtarget.com/tutorial/Set-up-PowerShell-script-block-logging-for-added-security
|
|
tags:
|
|
analytic_story:
|
|
- DarkSide Ransomware
|
|
- Ransomware
|
|
- Revil Ransomware
|
|
automated_detection_testing: passed
|
|
confidence: 90
|
|
context:
|
|
- Source:Endpoint
|
|
- Stage:Execution
|
|
dataset:
|
|
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/revil/inf1/windows-powershell.log
|
|
impact: 90
|
|
kill_chain_phases:
|
|
- Exploitation
|
|
message: An attempt to delete ShadowCopy was performed using PowerShell on $ComputerName$
|
|
by $User$.
|
|
mitre_attack_id:
|
|
- T1490
|
|
observable:
|
|
- name: User
|
|
type: User
|
|
role:
|
|
- Victim
|
|
- name: ComputerName
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- EventCode
|
|
- Message
|
|
- ComputerName
|
|
- User
|
|
risk_score: 81
|
|
security_domain: endpoint
|