Files
splunk-security_content/detections/endpoint/disable_defender_enhanced_notification.yml
2021-11-10 16:16:30 +00:00

66 lines
2.3 KiB
YAML

name: Disable Defender Enhanced Notification
id: dc65678c-301f-11ec-8e30-acde48001122
version: 1
date: '2021-10-18'
author: Teoderick Contreras, Splunk
type: TTP
datamodel:
- Endpoint
description: This analytic is to detect a suspicious modification of registry to disable
windows defender feature. This technique is to bypassed or evade detection from
Windows Defender AV product specially the Enhanced Notification feature wher user
or admin set to show or display alerts.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Registry where Registry.registry_path = "*Microsoft\\Windows
Defender\\Reporting*" Registry.registry_value_name = DisableEnhancedNotifications
Registry.registry_value_data = 0x00000001 by Registry.dest Registry.user Registry.registry_path
Registry.registry_value_name Registry.registry_value_data | `drop_dm_object_name(Registry)`
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `disable_defender_enhanced_notification_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the registry value name, registry path, and registry value data executions
from your endpoints. If you are using Sysmon, you must have at least version 6.0.4
of the Sysmon TA.
known_false_positives: user may choose to disable windows defender AV
references:
- https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
tags:
analytic_story:
- IceID
automated_detection_testing: passed
confidence: 70
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/icedid/disable_av/sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
message: modified/added/deleted registry entry $registry_path$ in $dest$
mitre_attack_id:
- T1562.001
- T1562
observable:
- name: dest
type: Hostname
role:
- Victim
- name: user
type: user
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.dest
- Registry.user
- Registry.registry_value_name
- Registry.registry_key_name
- Registry.registry_path
- Registry.registry_value_data
risk_score: 49
security_domain: endpoint