Files
splunk-security_content/stories/disabling_security_tools.yml
2020-04-29 13:01:45 +02:00

29 lines
1.6 KiB
YAML

name: Disabling Security Tools
id: fcc27099-46a0-46b0-a271-5c7dab56b6f1
version: '2.0'
date: '2020-02-04'
description: Looks for activities and techniques associated with the disabling of
security tools on a Windows system, such as suspicious `reg.exe` processes, processes
launching netsh, and many others.
narrative: Attackers employ a variety of tactics in order to avoid detection and operate
without barriers. This often involves modifying the configuration of security tools
to get around them or explicitly disabling them to prevent them from running. This
Analytic Story includes searches that look for activity consistent with attackers
attempting to disable various security mechanisms. Such activity may involve monitoring
for suspicious registry activity, as this is where much of the configuration for
Windows and various other programs reside, or explicitly attempting to shut down
security-related services. Other times, attackers attempt various tricks to prevent
specific programs from running, such as adding the certificates with which the security
tools are signed to a blacklist (which would prevent them from running).
author: Rico Valdez, Splunk
type: ESCU
references:
- https://attack.mitre.org/wiki/Technique/T1089
- https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/
- https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf
tags:
analytics_story: Disabling Security Tools
usecase: Security Monitoring
category:
- Adversary Tactics