Files
splunk-security_content/detections/endpoint/disable_defender_blockatfirstseen_feature.yml
2021-11-10 16:16:30 +00:00

66 lines
2.3 KiB
YAML

name: Disable Defender BlockAtFirstSeen Feature
id: 2dd719ac-3021-11ec-97b4-acde48001122
version: 1
date: '2021-10-18'
author: Teoderick Contreras
type: TTP
datamodel:
- Endpoint
description: This analytic is to detect a suspicious modification of registry to disable
windows defender feature. This technique is to bypassed or evade detection from
Windows Defender AV product specially the BlockAtFirstSeen feature where it block
suspicious file first seen in the host.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*\\Microsoft\\Windows
Defender\\SpyNet*" Registry.registry_value_name = DisableBlockAtFirstSeen Registry.registry_value_data
= 0x00000001 by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name
Registry.registry_value_data | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)` | `disable_defender_blockatfirstseen_feature_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the registry value name, registry path, and registry value data from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: admin or user may choose to disable windows defender product
references:
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
tags:
analytic_story:
- IceID
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
message: modified/added/deleted registry entry $registry_path$ in $dest$
mitre_attack_id:
- T1562.001
- T1562
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: user
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.dest
- Registry.user
- Registry.registry_value_name
- Registry.registry_key_name
- Registry.registry_path
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint