Files
splunk-security_content/docs/_posts/2021-12-07-fsutil_zeroing_file.md
2021-12-09 13:51:31 -05:00

4.0 KiB

title, excerpt, categories, last_modified_at, toc, toc_label, tags
title excerpt categories last_modified_at toc toc_label tags
Fsutil Zeroing File Indicator Removal on Host
Endpoint
2021-12-07 true
Indicator Removal on Host
Defense Evasion
Splunk Behavioral Analytics
Endpoint_Processes

Try in Splunk Security Cloud{: .btn .btn--success}

Description

This search is to detect a suspicious fsutil process to zeroing a target file. This technique was seen in lockbit ransomware where it tries to zero out its malware path as part of its defense evasion after encrypting the compromised host.

  • Type: TTP
  • Product: Splunk Behavioral Analytics
  • Datamodel: Endpoint_Processes
  • Last Updated: 2021-12-07
  • Author: Michael Haag, Splunk
  • ID: f792cdc9-43ee-4429-a3c0-ffce4fed1a85

ATT&CK

ID Technique Tactic
T1070 Indicator Removal on Host Defense Evasion

| from read_ssa_enriched_events() 
| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) 
| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" AND (like (cmd_line, "%setzerodata%")) 
| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) 
| into write_ssa_detected_events();

Associated Analytic Story

How To Implement

To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used.

Required field

  • _time
  • dest_device_id
  • process_name
  • parent_process_name
  • process_path
  • dest_user_id
  • process
  • cmd_line

Kill Chain Phase

  • Exploitation

Known False Positives

System administrators or scripts may delete user accounts via this technique. Filter as needed.

RBA

Risk Score Impact Confidence Message
54.0 60 90 An instance of parent_process_name spawning process_name was identified on endpoint dest_device_id by user dest_user_id atempting to perform file deletion.

Reference

Test Dataset

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range

source | version: 1