mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
28 lines
1.2 KiB
YAML
28 lines
1.2 KiB
YAML
name: Windows Persistence Techniques
|
|
id: 30874d4f-20a1-488f-85ec-5d52ef74e3f9
|
|
version: 2
|
|
date: '2018-05-31'
|
|
author: Bhavin Patel, Splunk
|
|
status: production
|
|
description: Monitor for activities and techniques associated with maintaining persistence
|
|
on a Windows system--a sign that an adversary may have compromised your environment.
|
|
narrative: Maintaining persistence is one of the first steps taken by attackers after
|
|
the initial compromise. Attackers leverage various custom and built-in tools to
|
|
ensure survivability and persistent access within a compromised enterprise. This
|
|
Analytic Story provides searches to help you identify various behaviors used by
|
|
attackers to maintain persistent access to a Windows environment.
|
|
references:
|
|
- http://www.fuzzysecurity.com/tutorials/19.html
|
|
- https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html
|
|
- http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/
|
|
- https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
|
|
- https://www.youtube.com/watch?v=dq2Hv7J9fvk
|
|
tags:
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|